Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
minLevel2
maxLevel2
typeflat

Purpose

The Windows System Audit Activeboard performs detailed system-level analysis on the Windows host by analyzing system events, account login statuses, and policy changes.

Expand
titleWatch video tutorialIncluded widgets

Filter by Host: Select input

Events Over Time: Line chart widget

More Recent Audit Events: Table widget

Total Audit Success: Simple value widget

Account logons: Column chart widget

Processes created: Table widget

Total Audit Failures: Simple value widget

Accounts with 10 or more failed loggons per hour: Pie chart widget

Audit Policy changes: Table widget

Widget Connector
overlayyoutube
_templatecom/atlassian/confluence/extra/widgetconnector/templates/youtube.vm
width600px
urlhttps://www.youtube.com/watch?v=QEh86RxXDFc
height300px
Pre-requisites

Prerequisites

To run this Activeboard, you must have the following data sources available on your domain:

Open

Windows System Audit

Activeboard

Once you have installed the applicationActiveboard, you can access the Activeboard in the following ways:

Go to Exchange in the navigation and look for the Activeboard you want to open. Click Open.

Image Removed

Go to Activeboards in the navigation pane and use the filter to open the Activeboard you downloaded.

Image Removed

Info

Know more about Activeboards

Refer to Manage and filter Activeboards article to know how to work with Activeboards.

Exploring the Activeboard

When opening the Windows System Audit Activeboard, the following info display:

Image Removed NoteLoad data takes too long

use the Open button at the top right of the card in Exchange to access it and see the different widgets populated with the relevant data. You can also access the Activeboard area via the Navigation pane.

Image Added
Image Added
Audit Policy changes
Info

Data loading takes too long?

Sometimes some widgets take time to upload the data, it is possible to speed up the process by creating aggregation tasks. Refer to the Aggregation tasks article to learn how to do it.

Expand
titleClick here to see the details

Widget

Details

Image Removed

Filter by Host

Image Removed

Total Audit Success

Image Removed

Total Audit Failures

Image Removed

Events Over Time

Image Removed

Account logons

Image Removed

Accounts with 10 or more failed loggons per hour

Image Removed

More Recent Audit Events

Image Removed

Processes created

Image Removed

Use Activeboard

After installing and opening the Activeboard, you can use its widgets to visualize and monitor data. To do this, each widget offers a variety of customization and visualization options. Refer to Using widgets and Using inputs to know them all.