\n", " | name | \n", "hostIdentifier | \n", "calendarTime | \n", "unixTime | \n", "epoch | \n", "counter | \n", "numerics | \n", "action | \n", "decorations_host_uuid | \n", "decorations_username | \n", "... | \n", "columns_action | \n", "columns_atime | \n", "columns_category | \n", "columns_ctime | \n", "columns_mode | \n", "columns_mtime | \n", "columns_sha256 | \n", "columns_size | \n", "columns_target_path | \n", "columns_time | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
793 | \n", "fim | \n", "HOSTNAME | \n", "Fri Feb 3 11:52:32 2023 UTC | \n", "1675425152 | \n", "0 | \n", "8 | \n", "False | \n", "added | \n", "F7E6787D-B2D8-4830-854E-33AF0A1338B8 | \n", "\n", " | ... | \n", "DELETED | \n", "1675425150 | \n", "roothome | \n", "1675425150 | \n", "0600 | \n", "1675425150 | \n", "\n", " | 30306 | \n", "/root/.viminfo | \n", "1675425150 | \n", "
1 rows × 23 columns
\n", "\n", " | name | \n", "hostIdentifier | \n", "calendarTime | \n", "unixTime | \n", "epoch | \n", "counter | \n", "numerics | \n", "action | \n", "decorations_host_uuid | \n", "decorations_username | \n", "columns_cmdline | \n", "columns_euid | \n", "columns_name | \n", "columns_parent | \n", "columns_path | \n", "columns_pcmdline | \n", "columns_pid | \n", "columns_uid | \n", "columns_username | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
0 | \n", "pack_osquery-custom-pack2_processes | \n", "HOSTNAME | \n", "Fri Feb 3 06:28:25 2023 UTC | \n", "1675405705 | \n", "0 | \n", "876 | \n", "False | \n", "removed | \n", "F7E6787D-B2D8-4830-854E-33AF0A1338B8 | \n", "\n", " | /bin/sh /usr/local/scripts/audispd_report.sh | \n", "102 | \n", "sudo | \n", "54935 | \n", "\n", " | sudo -u syslog /usr/local/scripts/audispd_repo... | \n", "54940 | \n", "102 | \n", "syslog | \n", "
\n", " | name | \n", "hostIdentifier | \n", "calendarTime | \n", "unixTime | \n", "epoch | \n", "counter | \n", "numerics | \n", "action | \n", "decorations_host_uuid | \n", "decorations_username | \n", "columns_cmdline | \n", "columns_name | \n", "columns_path | \n", "columns_pcmdline | \n", "columns_pid | \n", "columns_username | \n", "columns_local_port | \n", "columns_md5 | \n", "columns_remote_address | \n", "columns_remote_port | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
90 | \n", "pack_osquery-custom-pack2_outbound_connections | \n", "HOSTNAME | \n", "Fri Feb 3 07:00:47 2023 UTC | \n", "1675407647 | \n", "0 | \n", "59 | \n", "False | \n", "removed | \n", "F7E6787D-B2D8-4830-854E-33AF0A1338B8 | \n", "\n", " | /usr/local/bin/prometheus --storage.tsdb.path=... | \n", "prometheus | \n", "/usr/local/bin/prometheus | \n", "/sbin/init | \n", "1510 | \n", "prometheus | \n", "34404 | \n", "\n", " | 10.8.0.77 | \n", "9100 | \n", "
\\n\"+\n", " \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n", " \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n", " \"
\\n\"+\n", " \"\\n\"+\n",
" \"from bokeh.resources import INLINE\\n\"+\n",
" \"output_notebook(resources=INLINE)\\n\"+\n",
" \"
\\n\"+\n",
" \"\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"