Document toolboxDocument toolbox

Activeboard: Data Source Monitor

Purpose

This Activeboard provides measurements around the data source of your domain. It includes tables that have a significant decrease in ingestion compared to the historical averages, total volume seen over the last month, hourly volume breakdown, as well as new and missing hosts, users, and firewalls.

Main area

Sources with no data today: Simple value widget

Total sources seen last 8 days: Simple value widget

Hourly event count of selected source: Line chart widget

Sources with less 50% of normal volume: Simple value widget

Total volume last 30 days: Simple value widget

Hourly ingrst volume (all sources): Area chart widget

Sources with less 50 % - 75 % of normal volume: Simple value widget

Data sources monitor: Table widget

 

Windows Hosts Information

Hosts not reporting: Table widget

New hosts: Table widget

 

Linux Host Information

Hosts not reporting: Table widget

New hosts: Table widget

 

User information

Users not reporting: Table widget

New users: Table widget

 

Firewall Hosts Information

Firewalls not reporting: Table widget

New firewalls: Table widget

 

Prerequisites

To use this Activeboard, you must have the following sources available on your domain:

Open Activeboard

Once you have installed the Activeboard, you can use the Open button at the top right of the card in Exchange to access it and see the different widgets populated with the relevant data. You can also access the Activeboard area via the Navigation pane.

Data loading takes too long?

Sometimes some widgets take time to upload the data, it is possible to speed up the process by creating aggregation tasks. Refer to the Aggregation tasks article to learn how to do it.

Use Activeboard

After installing and opening the Activeboard, you can use its widgets to visualize and monitor data. To do this, each widget offers a variety of customization and visualization options. Refer to Using widgets and Using inputs to know them all.