Skip to main content

Responses are generated using AI and may contain mistakes.

DashboardDashboards Guide

NSA Detections Overview

This dashboard provides an overview of the alerts being triggered in your New-Scale Analytics environment. Based on a series of filters that search for alert events, the dashboard visualizes the volume of alerts by various metrics and provides a count of different alert types.

Note

This pre-built dashboard is available only with a New-Scale Analytics license.

Dashboard Filters

You can filter the data in the dashboard visualizations by the alert stages and by the alert creation time stamps.

To set the filters:

  1. Click the drop-down arrow (icon-expand.png)on the right to expand the filters panel.

    nsa-detections-overview-filters-collapsed.png
  2. Update either of the available filters.

    • In the Alerts: Stage filter, select one or more alert stages.

    • In the Alerts: Creation Timestamp Time filter, select an operator from the first drop down menu and then enter or select values in the subsequent fields, depending on the selected operator.

    nsa-detections-overview-filters.png
  3. Click Apply. The updated filters are applied to the visualizations on the dashboard.

NSA Alerts by Use Case

This pie chart shows the total number of alerts trigger, and shows the count proportions by use case. To view the represented values, hover your cursor over the graph slices. To drill down into a specific use case and view the underlying alert events, click a graph slice, and then click Show All. A dialog box opens and lists the first 500 alerts for the selected use case.

NSA Alerts by MITRE Tactics

This bar chart shows the count of alerts by MITRE tactic over the selected time range. To view the represented values, hover your cursor over the graph bars. To drill down into a specific MITRE tactic and view the underlying alert events, click a graph bar, and then click Show All. A dialog box opens and lists the first 500 alerts for the selected MITRE tactic.

NSA Alerts by TTP - Top 10

This Sankey chart shows the count of alerts for MITRE techniques, for the 10 techniques with the highest alert counts, and breaks the counts down by specific MITRE tactics. The techniques are listed by ID and name on the left side of the chart. The tactics are listed by ID and name on the right side. The connections between them show how the alert count for each technique on left is broken down across the tactics on the right. This chart can help you monitor alert activity from different techniques to ensure that traffic and behavior matches expectations.

To highlight the links between the techniques and tactics, and to view their count values, hover your cursor over the graph connectors. To view the underlying alert events of a value, click the link, and then click Show Results in Search.

nsa-detections-sankey-annotated.png

Alerts Count Over Time

This area chart shows the count trend of alerts by rule trigger events over the selected time range. To view the values represented in the chart, move your cursor over the graph area to display the date data points. To drill down into a date, for a specific rule, and view the underlying alert events, click Show All. A dialog box opens and lists the first 500 alerts for the selected date of the specified rule.

Count of Context Alerts

This table provides a count of alerts triggered by rules related to context table alerts (rules whose Rule ID begins with Cntx-). To sort the table, click the heading of any column that you want to sort the data by. Then use the arrow icon to change between ascending (icon-arrow-ascend.png) and descending (icon-arrow-descend.png) orders. To view all the table rows, you may need to use the scroll bar on the right.

To view the underlying events, in the Count column, click a count value and then click Show Results in Search.

Count of Fact Alerts

This table provides a count of alerts triggered by rules related to fact alerts (rules whose Rule ID begins with Fact-). To sort the table, click the heading of any column that you want to sort the data by. Then use the arrow icon to change between ascending (icon-arrow-ascend.png) and descending (icon-arrow-descend.png) orders. To view all the table rows, you may need to use the scroll bar on the right.

To view the underlying events, in the Count column, click a count value and then click Show Results in Search.

Count of Profiled Alerts

This table provides a count of alerts triggered by rules related to profile alerts (rules whose Rule ID begins with Prof-, NumSP, NumDCP, or NumCP). To sort the table, click the heading of any column that you want to sort the data by. Then use the arrow icon to change between ascending (icon-arrow-ascend.png) and descending (icon-arrow-descend.png) orders. To view all the table rows, you may need to use the scroll bar on the right.

To view the underlying events, in the Count column, click a count value and then click Show Results in Search.