From f960a4d2887595d13cd2e94d209db45df7884b9d Mon Sep 17 00:00:00 2001 From: Scott Brumley Date: Thu, 24 Sep 2026 17:47:44 -0400 Subject: [PATCH] fix(soc-framework-nist-ir-ai): match the ingestion widget header to its title Same defect and same fix as the base pack. The 23 Sep rename off the 'lag' framing updated the viewOptions header and left the phrase's view clause carrying the old text: viewOptions header : "Ingestion Time by Source (Avg Minutes)" phrase header : "Alert Ingestion Lag by Source (Avg Minutes)" The tile caption still read 'Alert Ingestion Lag', the framing the rename existed to remove. Affects the Value Metrics pair. Verified by comparing both header values programmatically across every widget in the pack. --- .../XSIAMDashboards/NIST_IR_AI_Value_Metrics.json | 2 +- .../XSIAMDashboards/NIST_IR_AI_Value_Metrics_Shadow.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics.json b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics.json index 5ad7e397..37b12067 100644 --- a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics.json +++ b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics.json @@ -1850,7 +1850,7 @@ "creation_time": 1773887140953, "description": "Time from alert anchor timestamp to arrival in XSIAM, by source (ingestion lag).", "data": { - "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Alert Ingestion Lag by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", + "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Ingestion Time by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", "time_frame": { "relativeTime": 86400000 }, diff --git a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics_Shadow.json b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics_Shadow.json index c15f8df0..609535e8 100644 --- a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics_Shadow.json +++ b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Metrics_Shadow.json @@ -1850,7 +1850,7 @@ "creation_time": 1773887140953, "description": "Time from alert anchor timestamp to arrival in XSIAM, by source (ingestion lag).", "data": { - "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Alert Ingestion Lag by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", + "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Ingestion Time by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", "time_frame": { "relativeTime": 86400000 },