Skip to main content

DashboardDashboards Guide

Table of Contents

Windows Audit Failure Summary by Hosts Dashboard

This dashboard provides an overview of Windows audit failure events by the hosts in your organization.

Note

This dashboard assists you in complying with the following regulatory requirements: NIST 800-53 SI-4, CJIS 5.4.2, PMC 10.1, NIST 800-53 AC-2(12), NIST 800-66 R1 4.1.7, HIPAA 164.308-a1, SOX/Control Activities/Verification, NIST 800-66 R1 4.3.5, NIST 800-66 R1 4.15.5, NIST 800-53 AU-5, HIPAA 164.312-b, HIPAA 164.308-a3.

Time Range Filter

The Event : Approx Log Time filter sets the time range for the event data. The default setting is in the last 7 days. You can update this filter with a wide range of customizable settings.

To update the time range filter, click the arrow (icon-expand.png) on the right, under the Edit button, to expand the filters panel. In the Event : Approx Log Time filter, select an operator from the first drop down menu and then enter or select values in the subsequent fields, depending on the operator you selected. To save your filter changes, click Apply on the right side of the filter panel. The updated filter is applied to the visualization.

time-range-options.png

Number of Hosts with Windows Audit Failure Activity

This single value bar chart displays the number of unique hosts with Windows audit failure activity during the selected time range.

A single value-style visualization.

Top 10 Hosts with Windows Audit Failure Activity

This column chart shows the top 10 hosts with the most Windows audit failure events. To view the values represented on the chart, hover your pointer over the column bars. To view the underlying events of a value, click the bar, and then click Show Results in Search.

A selected column in a column chart displaying the 10 hosts with the most Windows audit failure events.

Windows Audit Failure Trends by Host

This area chart shows the count trends for Windows audit failure events on the different hosts over the selected time range. Move your pointer over a graph area to highlight it and display the represented count values. To view the underlying events of a value, click the data point, and then click Show Results in Search.

Windows-Failure-Audit-Trends-by-Host.png

Recent Windows Audit Failure Events

This table displays the raw log data of the last 20 Window audit failure events. Click the arrow icon on the table heading to change between ascending Sort-Up.png and descending Sort-Down.png order. To view all the table rows, use the scroll bar on the right.

A table displaying the raw log data of the last 20 user Windows audit failure events.