Skip to main content

Responses are generated using AI and may contain mistakes.

DashboardDashboards Guide

Project Collateral

The Project Collateral dashboard provides a count of the parsers ingesting data and the rule triggers being activated in your environment and it provides a list of the vendors and products that are the sources of that data.

Time Range Filter

The Event : Approx Log Time filter sets the time range for the event data. The default setting is in the last 7 days. You can update this filter with a wide range of customizable settings.

To update the time range filter, click the arrow (icon-expand.png) on the right, under the Edit button, to expand the filters panel. In the Event : Approx Log Time filter, select an operator from the first drop down menu and then enter or select values in the subsequent fields, depending on the operator you selected. To save your filter changes, click Apply on the right side of the filter panel. The updated filter is applied to the visualization.

time-range-options.png

Data Sources

This table visualization lists the non-Exabeam vendors and products that have provided data to your system over the selected time ranges. Click the heading of the column that you want to sort the data by. Then click the arrow icon in the column heading to change between ascending Sort-Up.png and descending Sort-Down.png sort orders. To view all the table rows, you may need to use the scroll bar on the right.

data-source.png

Parser, Vendor, and Activity Types

This table provides details about the parsers that have ingested data in the selected time range (listed in the MSG Type column), including the vendor and product the parsed data came from, the activity the data was part of, and the number of occurrences. Click the heading of the column that you want to sort the data by. Then click the arrow icon in the column heading to change between ascending Sort-Up.png and descending Sort-Down.png sort orders. To view all the table rows, you may need to use the scroll bar on the right.

To view the underlying events of a value in the Count column, click the value, and then click Show Results in Search.

parser-vendor-and-activity-types.png

Rules Triggered

This table visualization lists the ID, Name, and Count of rules that have been triggered by an anomaly alert in your system over the selected time ranges. Click the heading of the column that you want to sort the data by. Then click the arrow icon in the column heading to change between ascending Sort-Up.png and descending Sort-Down.png sort orders. To view all the table rows, you may need to use the scroll bar on the right.