Dashboards

Dashboards are used for monitoring your network and managing security-related events and activities. You can use pre-built system dashboards, or create your own dashboards using the variety of visualization widgets available in Fusion.

To get started using dashboards, see Quickstart: Dashboards.

📌

Pin dashboards directly to the left-hand menu in the Fusion Portal

Pinning a dashboard makes it show up directly on the left-hand menu of the Fusion Portal in the Dashboards section, making it available with a single click.

To pin a dashboard, click the in the first column of the dashboards table, then select Pin from the drop-down menu.

You will see a set of tabs when you click All under Dashboards on the left-hand menu.

Dashboard Tabs

Recent

The recent tab shows the last dashboards whether system default or custom sorted by last used and can show 10 dashboards at maximum. The first result will be the most recent usage. You can also choose to sort your results. The recent screen view and layout can be exported in CSV format.

Favorites

The favorites tab shows the all dashboards marked as favorite (the filled star icon). The first result will be the most recent usage. You can also choose to sort your recent results.

My Dashboards

When you use the ADD DASHBOARD button, you become the owner and author of those dashboards. All dashboards created and authored by you display on the My Dashboards page.

When creating a dashboard, you have the ability to set the dashboard to Public Visibility (public, in this case, means available to other users in your company only). Otherwise your dashboard remains private to your user only.

This setting is found in ADD DASHBOARD > Options.

Company Dashboards

Company dashboards are dashboards that you, or other users in your account, have created and marked as Public. Public dashboards means they are available to all the users in your account, not that they are available to the general public.

System Dashboards

Netography generates the system dashboards and they cannot be directly modified. The included widgets in each system dashboard can be pushed to global filters (GF), fullscreen sized, printed, and exported as CSV, PNG, and SVG.

The system dashboards can be copied and/or set as a Homepage or Company homepage when viewing the Home option in the left main menu.

Scheduled Dashboards

When viewing a dashboard, you can select the blue clock icon to bring up the Schedule Settings page for the dashoard. On this page you can create a schedule to generate and email the dashboard at a frequency of your choice. Any dashboards you create a schedule for will appear on the Scheduled Dashboards tab.

Netography System Dashboards

Security Overview Dashboard

The Security Overview dashboard is designed to provide a comprehensive overview of your security posture. It includes several line chart widgets that provide detailed information on various aspects of your network security:

  • The Bogon Flows chart displays the number of bogon flows detected by the system. Bogons are IP packets that originate from addresses that are not assigned to any specific organization or are otherwise reserved for special use
  • The Source IP Cardinality chart displays the number of unique source IP addresses detected by the system over a specified time period. This information can be used to identify potential threats and to track the spread of attacks.
  • The IP Reputation Flows chart displays the number of flows detected by the system that have been associated with known malicious IP addresses. This information can be used to quickly identify potential threats and to take appropriate action.
  • The Site chart displays the number of requests made to each site or domain on your network. This information can be used to identify potential security risks and to identify areas where additional monitoring or protection may be needed.
  • The Aggregate Risk chart provides an overview of the overall risk level of your network. This chart is based on a number of factors, including the number of alerts generated by the system, the severity of those alerts, and the overall security posture of your network.
  • The Source Country chart displays the number of flows originating from each country over a specified time period. This information can be used to identify potential threats originating from specific regions and to take appropriate action to mitigate those threats.
  • Threat breakdown - This bar graph provides an overview of the different types of threats detected on your network. It shows the number of incidents related to phishing, proxy, botnets, and windowsexploits. You can use this information to identify the most common types of threats on your network and take appropriate action to mitigate them.
  • Port Threat Breakdown - This bar graph is sorted by multiple ports and provides a breakdown of the different types of threats detected on specific ports on your network. This information can help you identify which ports are most vulnerable to attacks and take steps to secure them.
  • TCP Flag Distribution - This graph widget provides a distribution of the different types of TCP flags that are being used in your network traffic. It shows the number of incidents related to ACK, PSH, and SYN flags. This information can help you identify suspicious traffic patterns and take appropriate action to prevent attacks.

Traffic Overview Dashboard

The Traffic Overview Dashboard provides an overview of network traffic with hourly intervals. The dashboard includes six line graph widgets for Bitrate, Source IP Cardinality, Packets Rate, Flow Rate, Site, and Source Country. Additionally, two bar graphs for Protocol breakdown and Port Breakdown, and a scatter plot chart for ACK, PSH, FIN, SYN, and RST.

The line graph widgets display the hourly intervals for the following metrics:

  • Bitrate: Displays the amount of data transmitted per second in bits
  • Source IP Cardinality: Shows the number of unique source IP addresses
  • Packets Rate: Displays the rate at which packets are transmitted per second
  • Flow Rate: Shows the rate of data flow per second
  • Site: Displays the network traffic by site
  • Source Country: Shows the network traffic by source country

Protocol and Port breakdown bar graphs:

  • Protocol breakdown: Shows the percentage of network traffic for each protocol type. The protocol types included are TCP, DUP, IMP, and ICMP.
  • Port Breakdown: Displays the percentage of network traffic by multiple ports.
    Hovering over over the bars show the percentage value of each protocol type or port.

The TCP Flag Distribution widget displays a scatter plot chart of network traffic for ACK, PSH, FIN, SYN, and RST that can help identify the patterns and anomalies in network traffic.

Audit Log Activity Dashboard

The Audit Log Activity Dashboard provides an overview of user activity on the system. The dashboard includes four bar graph widgets for Top Users, Top Classes, Top Actions, and Audits. Additionally, there is a table called Last Events that displays the last events with filters for timestamp, class, subclass, action, user, and description.

The bar graph widgets display the top users, classes, actions, and audits. The data displayed in each widget is as follows:

  • Top Users: Shows the users who have performed the most actions.
  • Top Classes: Displays the classes that have been accessed the most.
  • Top Actions: Shows the most common actions performed on the system.
  • Audits: Displays the number of audits performed on the system.
    Each bar graph widget displays the top ten results by default, but the user can adjust the number of results displayed as per their requirement. The user can hover over the bars to see the number of occurrences for each user, class, action, or audit.

The Last Events table displays the latest events on the system. The user can click on any event to view more details.