The Detection dashboard is a centralized interface that presents your organization's alerts, status, and its anomalies detected within a network. You can filter data and view trends across different timeframes. Adjusting the timeframe provides insights into real-time activities, daily anomalies, and long-term patterns. Select the r option from the Show dropdown menu to adjust the timeframe for the displayed data.
The Settings icon on the dashboard allows you to add various widgets related to your view and appliance behavior. From the top-right corner of the dashboard, click and then choose your options.
The following summarizes the dashboard widgets:
Historical Chart
Displays alert traffic trends for predefined protocols (HTTP, DNS, SSH, and so on). You can choose to view traffic volume, alert count, or both over time. This chart helps track and visualize changes in network traffic and the frequency of alerts over time.
Packet Volume Over Time displays the number of packets received by NDR during the selected time period.
Note
This feature is available only to users with an Enterprise or Core license.
Flow Volume Over Time displays the number of flows processed by NDR during the selected time period.
Bytes Over Time displays the number of bytes processed by NDR during the selected time period.
Click the icon to customize trends and select specific protocols for analysis. For example, you can choose to view trends for HTTP, DNS, or SSH traffic individually, or in combination. This flexibility helps you track and visualize changes in network activity and alert frequency over time for specific protocols.
Note
You can select a maximum of 5 protocols.
Top Alerts
Displays the summary of recent alerts. The table has four columns:
Severity: This indicates the alert's severity level representing them in different colored segments.
Severity
Colored Segments
Critical
Red
High
Orange
Medium
Yellow
Low
Light Blue
Info
Gray
Date Created: This display the date and time when the alert was generated.
Alert Name: This provides the alert's name and specifies the number of affected assets for each alert.
Action: This indicates an action to be taken on the alert. You can only suppress alerts The system The system suppresses alerts based on source IP, source port, destination IP, destination port, and alert name. Any future alerts matching these criteria will not appear in the Top Alerts widget.
Click the icon to customize the number of top entries displayed.
Top Risky Conversations
Displays details about network communications identified as high-risk. The table provides the following columns:
Severity: This indicates the risk level of the conversation.
Last Updated: This shows the date and time when the information for the risky conversation was last updated.
Source IP: This lists the IP address from which the risky communication originated.
Destination IP: This lists the IP address to which the risky communication was directed.
Protocol: This indicates the network protocol used for the communication.
Volume: This is the amount of data transferred during a conversation between a Source IP and a Destination IP for a given Protocol. It is measured in units like KB (kilobytes) or MB (megabytes).
Note
The Top Risky Conversations widget is available only to users with an Enterprise or Core license.
Click the icon to customize the number of top entries displayed and whether to show priority assets only.
Top Risky Assets
Displays a list of assets that are generating critical alerts or exhibiting vulnerabilities, sorted by their risk scores. The widget helps you to quickly identify and prioritize the most vulnerable or compromised assets for further investigation and remediation. Each asset is assigned a risk score based on MITRE ATT&CK tactics and techniques.
Last Updated: This displays the date and time the asset's risk information was most recently refreshed.
Asset Details: This provides an identifier for the asset, in this case, an IP address.
Type: This categorizes the asset based on its operational environment or function. It clearly labels assets as "Enterprise," indicating that they belong to the traditional IT network. For IoT/ICS, you can see "IoT," "ICS," or similar classifications.
OS: This displays an icon representing the operating system of the asset.
Watch: This provides a mechanism to watch or monitor a specific asset. Clicking the eye icon will enable or disable a monitoring function.
Note
This feature is available only to users with an Enterprise or Core license.
Alerts by Country
Visualizes the geographic distribution of alerts. The map highlights specific countries in different colors to indicate where alerts are originating or being detected.
Alerts by MITRE ATT&CK
The chart visualizes the distribution of detected alerts categorized by their corresponding MITRE ATT&CK tactics. Each bar represents a specific MITRE ATT&CK tactic, and its length corresponds to the number of alerts associated with that tactic. A numerical value at the end of each bar indicates the exact count of the alerts.
Hosts OS vs Severity
Visualizes the distribution of alerts based on the operating system of the hosts and the severity of those alerts.
The outer ring of the donut chart represents the host operating systems, with different colored segments indicating:
Blue: Windows
Green: MacOS
Lime Green: Linux
Purple: Other
The inner ring, labeled "Hosts OS severity," represents the severity of the alerts, with different colored segments indicating:
Red: Critical
Orange: High
Yellow: Medium
Light Blue: Low
Gray: Info
Note
This feature is available only to users with an Enterprise or Core license.