Purpose
This Activeboard provides measurements around the data source of your domain. It includes tables that have a significant decrease in ingestion compared to the historical averages, total volume seen over the last month, hourly volume breakdown, as well as new and missing hosts, users, and firewalls.
Pre-requisites
To use the Data Source Monitor Activeboard you must have the following sources available on your domain:
siem.logtrust.collector.counter
box.all.win
learn morebox.unix
learn morefirewall.all.traffic
learn more
Open Security Operations Executive Overview
Once you have installed the Activeboard, you can access it in the following ways:
Go to Exchange in the navigation pane and look for the Activeboard you want to open. Click Open.
Go to Activeboards in the navigation pane and use the filter to open the Activeboard you downloaded.
Know more about Activeboards
Refer to Manage and filter Activeboards article to know how to work with Activeboards.
Exploring the Activeboard
When opening the Data Source Monitor Activeboard the following info is displayed. This Activeboard is divided into different areas:
Load data takes too long
Sometimes some widgets take time to upload the data, it is possible to speed up the process by creating aggregation tasks. Refer to Aggregation tasks article to learn how to do it.