Skip to content

General Overview

This section provides general SIEM information, with the option to filter by date range for specific periods.

SIEM Dashboard Metrics

Displayed data includes:

IndicatorColorDescription
Last 24hPurpleNumber of alerts in the last 24 hours, comparison with yesterday, and alert rate per hour
Last WeekSecondaryTotal alerts in the last 7 days
Resp. TimeYellowAverage alert response time in hours
ResolutionGreenPercentage rate of resolved alerts
Total DomainsPurpleTotal number of monitored domains
Active DomainsGreenDomains currently online with availability percentage
Critical IssuesRedNumber and percentage of unresolved critical alerts
MTTAYellowMean Time To Acknowledge: average time needed to acknowledge an alert

Alert Trend gives a quick view of the alert severity that is triggering most often.

Alert Trends Chart

  • Hourly Trend: shows when alerts are arriving at the SIEM.
  • Severity Distribution: shows the percentage distribution of alert severities.
  • Most Frequent Types: shows the top 5 alert types in the SIEM.
  • Most Active IPs: shows the IP addresses attacking the configured SIEM domains most often.

IP Activity and Distribution