From 938bcef1fad3b86af4ec740e2ee00b600095e144 Mon Sep 17 00:00:00 2001 From: Scott Brumley Date: Thu, 24 Sep 2026 18:08:12 -0400 Subject: [PATCH] fix(soc-optimization-unified): make the health dashboard distinguish live from historical The headline tiles were 30-day aggregates, so a DC opening the dashboard today read a 60% command error rate and would start firefighting something that resolved five days ago. Measured on a reference tenant, same query, three windows: 30 days 60% (3,830 of 6,335) 7 days 5% (127 of 2,626) 24 hours 0 failures Changes: - new 'Failures in the Last 24h' tile, first in the row - the live signal - Command Error Rate, Failed Commands and Minutes Credited to Failed Commands move to a 7-day window and are labelled (7d) - the trend, breakdowns and drilldown stay at 30 days, which is what they are for A high 7-day rate beside a zero 24h count now reads as 'already resolved' rather than 'on fire'. That distinction was not available before, and its absence produced two false escalations in one session - the 66% error rate and the socfw-post-to-dataset write failures were both single-period events already over by the time they were found. --- .../SOCFW_Framework_Health.json | 125 +++++++++++++++--- 1 file changed, 104 insertions(+), 21 deletions(-) diff --git a/Packs/soc-optimization-unified/XSIAMDashboards/SOCFW_Framework_Health.json b/Packs/soc-optimization-unified/XSIAMDashboards/SOCFW_Framework_Health.json index 79078df0..1aeaa18d 100644 --- a/Packs/soc-optimization-unified/XSIAMDashboards/SOCFW_Framework_Health.json +++ b/Packs/soc-optimization-unified/XSIAMDashboards/SOCFW_Framework_Health.json @@ -10,12 +10,47 @@ { "id": "row-1200", "data": [ + { + "key": "xql_1790000000010", + "data": { + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\"\n| alter failed = if(has_error = true, 1, 0)\n| comp sum(failed) as failed_last_24h\n| view graph type = single subtype = standard header = \"Failures in the Last 24h\" yaxis = failed_last_24h", + "time_frame": { + "relativeTime": 86400000 + }, + "viewOptions": { + "type": "single", + "commands": [ + { + "command": { + "op": "=", + "name": "subtype", + "value": "standard" + } + }, + { + "command": { + "op": "=", + "name": "header", + "value": "\"Failures in the Last 24h\"" + } + }, + { + "command": { + "op": "=", + "name": "yaxis", + "value": "failed_last_24h" + } + } + ] + } + } + }, { "key": "xql_1790000000001", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\"\n| alter failed = if(has_error = true, 1, 0)\n| comp sum(failed) as failed_commands, count() as total_commands\n| alter error_rate_pct = round(multiply(divide(failed_commands, total_commands), 100))\n| view graph type = single subtype = standard header = \"Command Error Rate (%)\" yaxis = error_rate_pct", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\"\n| alter failed = if(has_error = true, 1, 0)\n| comp sum(failed) as failed_commands, count() as total_commands\n| alter error_rate_pct = round(multiply(divide(failed_commands, total_commands), 100))\n| view graph type = single subtype = standard header = \"Command Error Rate (%) (7d)\" yaxis = error_rate_pct", "time_frame": { - "relativeTime": 2592000000 + "relativeTime": 604800000 }, "viewOptions": { "type": "single", @@ -31,7 +66,7 @@ "command": { "op": "=", "name": "header", - "value": "\"Command Error Rate (%)\"" + "value": "\"Command Error Rate (%) (7d)\"" } }, { @@ -48,9 +83,9 @@ { "key": "xql_1790000000002", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| comp count() as failed_commands\n| view graph type = single subtype = standard header = \"Failed Commands\" yaxis = failed_commands", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| comp count() as failed_commands\n| view graph type = single subtype = standard header = \"Failed Commands (7d)\" yaxis = failed_commands", "time_frame": { - "relativeTime": 2592000000 + "relativeTime": 604800000 }, "viewOptions": { "type": "single", @@ -66,7 +101,7 @@ "command": { "op": "=", "name": "header", - "value": "\"Failed Commands\"" + "value": "\"Failed Commands (7d)\"" } }, { @@ -83,9 +118,9 @@ { "key": "xql_1790000000003", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| alter m = to_integer(action_time_minutes)\n| filter m != null\n| comp sum(m) as minutes_lost\n| view graph type = single subtype = standard header = \"Minutes Credited to Failed Commands\" yaxis = minutes_lost", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| alter m = to_integer(action_time_minutes)\n| filter m != null\n| comp sum(m) as minutes_lost\n| view graph type = single subtype = standard header = \"Minutes Credited to Failed Commands (7d)\" yaxis = minutes_lost", "time_frame": { - "relativeTime": 2592000000 + "relativeTime": 604800000 }, "viewOptions": { "type": "single", @@ -101,7 +136,7 @@ "command": { "op": "=", "name": "header", - "value": "\"Minutes Credited to Failed Commands\"" + "value": "\"Minutes Credited to Failed Commands (7d)\"" } }, { @@ -372,13 +407,13 @@ "widgets_data": [ { "widget_key": "xql_1790000000001", - "title": "Command Error Rate (%)", + "title": "Command Error Rate (%) (7d)", "creation_time": 1776770375262, "description": "Share of Universal Command executions flagged has_error over the window. The headline framework-health number.", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\"\n| alter failed = if(has_error = true, 1, 0)\n| comp sum(failed) as failed_commands, count() as total_commands\n| alter error_rate_pct = round(multiply(divide(failed_commands, total_commands), 100))\n| view graph type = single subtype = standard header = \"Command Error Rate (%)\" yaxis = error_rate_pct", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\"\n| alter failed = if(has_error = true, 1, 0)\n| comp sum(failed) as failed_commands, count() as total_commands\n| alter error_rate_pct = round(multiply(divide(failed_commands, total_commands), 100))\n| view graph type = single subtype = standard header = \"Command Error Rate (%) (7d)\" yaxis = error_rate_pct", "time_frame": { - "relativeTime": 2592000000 + "relativeTime": 604800000 }, "viewOptions": { "type": "single", @@ -394,7 +429,7 @@ "command": { "op": "=", "name": "header", - "value": "\"Command Error Rate (%)\"" + "value": "\"Command Error Rate (%) (7d)\"" } }, { @@ -420,13 +455,13 @@ }, { "widget_key": "xql_1790000000002", - "title": "Failed Commands", + "title": "Failed Commands (7d)", "creation_time": 1776770375262, "description": "Count of command executions with has_error = true. Read beside the error rate; a low rate on high volume still matters.", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| comp count() as failed_commands\n| view graph type = single subtype = standard header = \"Failed Commands\" yaxis = failed_commands", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| comp count() as failed_commands\n| view graph type = single subtype = standard header = \"Failed Commands (7d)\" yaxis = failed_commands", "time_frame": { - "relativeTime": 2592000000 + "relativeTime": 604800000 }, "viewOptions": { "type": "single", @@ -442,7 +477,7 @@ "command": { "op": "=", "name": "header", - "value": "\"Failed Commands\"" + "value": "\"Failed Commands (7d)\"" } }, { @@ -468,13 +503,13 @@ }, { "widget_key": "xql_1790000000003", - "title": "Minutes Credited to Failed Commands", + "title": "Minutes Credited to Failed Commands (7d)", "creation_time": 1776770375262, "description": "Time the value dashboards would attribute to commands that never ran. Compare against hours returned.", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| alter m = to_integer(action_time_minutes)\n| filter m != null\n| comp sum(m) as minutes_lost\n| view graph type = single subtype = standard header = \"Minutes Credited to Failed Commands\" yaxis = minutes_lost", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\" and has_error = true\n| alter m = to_integer(action_time_minutes)\n| filter m != null\n| comp sum(m) as minutes_lost\n| view graph type = single subtype = standard header = \"Minutes Credited to Failed Commands (7d)\" yaxis = minutes_lost", "time_frame": { - "relativeTime": 2592000000 + "relativeTime": 604800000 }, "viewOptions": { "type": "single", @@ -490,7 +525,7 @@ "command": { "op": "=", "name": "header", - "value": "\"Minutes Credited to Failed Commands\"" + "value": "\"Minutes Credited to Failed Commands (7d)\"" } }, { @@ -821,6 +856,54 @@ "creator_mail": "N/A", "is_public": true, "is_predefined": false + }, + { + "widget_key": "xql_1790000000010", + "title": "Failures in the Last 24h", + "creation_time": 1776770375262, + "description": "Live signal. The rate and count beside it are 7-day figures; this one answers 'is it broken now'. A high 7-day rate with zero here means it already resolved.", + "data": { + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| filter event_type = \"command\"\n| alter failed = if(has_error = true, 1, 0)\n| comp sum(failed) as failed_last_24h\n| view graph type = single subtype = standard header = \"Failures in the Last 24h\" yaxis = failed_last_24h", + "time_frame": { + "relativeTime": 86400000 + }, + "viewOptions": { + "type": "single", + "commands": [ + { + "command": { + "op": "=", + "name": "subtype", + "value": "standard" + } + }, + { + "command": { + "op": "=", + "name": "header", + "value": "\"Failures in the Last 24h\"" + } + }, + { + "command": { + "op": "=", + "name": "yaxis", + "value": "failed_last_24h" + } + } + ] + } + }, + "support_time_range": true, + "additional_info": { + "query_tables": [ + "xsiam_socfw_ir_execution_raw" + ], + "query_uses_library": false + }, + "creator_mail": "N/A", + "is_public": true, + "is_predefined": false } ], "fromVersion": "8.4.0"