diff --git a/apps/zui/src/plugins/brimcap/zeek/correlations.ts b/apps/zui/src/plugins/brimcap/zeek/correlations.ts index a77472eb62..753edff779 100644 --- a/apps/zui/src/plugins/brimcap/zeek/correlations.ts +++ b/apps/zui/src/plugins/brimcap/zeek/correlations.ts @@ -29,7 +29,7 @@ export function activateZeekCorrelations() { return zedScript` from ${session.poolName} | md5==${getMd5()} - | count() by tx_hosts + | count() by tx_host:=id.resp_h | sort -r | head 5` }, @@ -41,7 +41,7 @@ export function activateZeekCorrelations() { return zedScript` from ${session.poolName} | md5==${getMd5()} - | count() by rx_hosts + | count() by rx_host:=id.orig_h | sort -r | head 5` }, diff --git a/apps/zui/src/plugins/brimcap/zeek/queries.ts b/apps/zui/src/plugins/brimcap/zeek/queries.ts index 331063b12c..bbad2c4103 100644 --- a/apps/zui/src/plugins/brimcap/zeek/queries.ts +++ b/apps/zui/src/plugins/brimcap/zeek/queries.ts @@ -6,7 +6,7 @@ export function uidQuery(pool: string, uid: string) { } export function uidFilter(uid: string) { - return zedScript`uid==${uid} or ${uid} in conn_uids or ${uid} in uids or referenced_file.uid==${uid}` + return zedScript`uid==${uid} or ${uid} in uids or referenced_file.uid==${uid}` } export function communityConnFilter(data: CommunityConnArgs) { @@ -25,6 +25,7 @@ export function findConnLog(pool: string, uid: string) { | (` + uidFilter(uid) + `) + | _path=="conn" | is(ts,