Protegrity provides out-of-the-box visualization for viewing the data. The configuration used for the visualization are provided here. This helps better understand and interpret the data shown on the various graphs and charts.
The configuration of visualizations created in the earlier versions of the Audit Store Dashboards are retained after the ESA is upgraded. Protegrity provides default visualizations with version 10.1.0. If the title of an existing visualization matches the new visualization provided by Protegrity, then a duplicate entry is visible. Use the date and time stamp to identify and rename the existing visualizations.
Do not delete or modify the configuration or details of the visualizations provided by Protegrity. To customize the visualization, create a copy of the visualization and perform the customization on the copy of the visualization.
To view visualizations:
Log in to the ESA.
Navigate to Audit Store > Dashboard.
The Audit Store Dashboards appear in a new window. Click Open in a new tab if the dashboard is not displayed.
From the navigation panel, click Visualize.
Create and view visualizations from here.
Click a visualization to view it.
User Activity Across Date Range
Description: The user activity during the date range specified.
Type: Heat Map
Filter: Audit Index Logtypes
Configuration:
Index: pty_insight_*audit*
Metrics:
Value: Sum
Field: cnt
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum interval: Day
Y-axis
Sub aggregation: Terms
Field: protection.policy_user.keyword
Order by: Metric:Sum of cnt
Order: Descending
Size: 1
Custom label: Policy Users
Sensitive Activity by Date
Description: The data element usage on a daily basis.
Type: Line
Filter: Audit Index Logtypes
Configuration:
Index: pty_insight_*audit*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum interval: Day
Custom label: Date
Split series
Sub aggregation: Terms
Field: protection.dataelement.keyword
Order by: Metric:Count
Order: Descending
Size: 10
Custom label: Operation Count
Unauthorized Access By Username
Description: Top 10 Unauthorized Protect and Unprotect operation counts per user.
Type: Vertical Bar
Filter 1: Audit Index Logtypes
Filter 2: protection.audit_code: 3
Configuration:
Index: pty_insight_*audit*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Terms
Field: protection.policy_user.keyword
Order by: Metric:Count
Order: Descending
Size: 10
Custom label: Top 10 Policy Users
Split series
Sub aggregation: Filters
Filter 1-Protect: level=‘Error’
Filter 2-Unprotect: level=‘WARNING’
System Report - High & Critical Events of Audit Indices
Description: The chart reporting high and critical events from the Audit index.
Type: Vertical Bar
Filter: Severity Level : (High & Critical)
Configuration:
Index: pty_insight_analytics*audits_*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum Interval: Auto
Custom label: Date
Split series
Sub aggregation: Terms
Field: level.keyword
Order by: Metric:Count
Order: Descending
Size: 20
Split series
Sub aggregation: Terms
Field: origin.hostname.keyword
Order by: Metric:Count
Order: Descending
Size: 50
Custom label: Server
System Report - High & Critical Events of Policy Logs Index
Description: The chart reporting high and critical events from the Policy index.
Type: Vertical Bar
Filter: Severity Level : (High & Critical)
Configuration:
Index: pty_insight_analytics*policy_log_*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum Interval: Auto
Custom label: Date
Split series
Sub aggregation: Terms
Field: level.keyword
Order by: Metric:Count
Order: Descending
Size: 20
Split series
Sub aggregation: Terms
Field: origin.hostname.keyword
Order by: Metric:Count
Order: Descending
Size: 50
Custom label: Server
System Report - High & Critical Events of Troubleshooting Logs Index
Description: The chart reporting high and critical events from the Troubleshooting index.
Type: Vertical Bar
Filter: Severity Level : (High & Critical)
Configuration:
Index: pty_insight_analytics*troubleshooting_*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum Interval: Auto
Custom label: Date
Split series
Sub aggregation: Terms
Field: level.keyword
Order by: Metric:Count
Order: Descending
Size: 20
Split series
Sub aggregation: Terms
Field: origin.hostname.keyword
Order by: Metric:Count
Order: Descending
Size: 50
Custom label: Server
Data Element Usage Intensity Of Users per Protect operation
Description: The chart shows the data element usage intensity of users per protect operation. It displays the top 10 data elements used by the top five users.
Type: Heat Map
Filter 1: protection.operation.keyword: Protect
Filter 2: Audit Index Logtypes
Configuration:
Index: pty_insight_*audit*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Terms
Field: protection.policy_user.keyword
Order by: Metric: Count
Order: Descending
Size: 5
Y-axis
Sub aggregation: Terms
Field: protection.dataelement.keyword
Order by: Metric:Count
Order: Descending
Size: 10
Data Element Usage Intensity Of Users per Reprotect operation
Description: The chart shows the data element usage intensity of users per reprotect operation. It displays the top 10 data elements used by the top five users.
Type: Heat Map
Filter 1: protection.operation.keyword: Reprotect
Filter 2: Audit Index Logtypes
Configuration:
Index: pty_insight_*audit*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Terms
Field: protection.policy_user.keyword
Order by: Metric: Count
Order: Descending
Size: 5
Y-axis
Sub aggregation: Terms
Field: protection.dataelement.keyword
Order by: Metric:Count
Order: Descending
Size: 10
Data Element Usage Intensity Of Users per Unprotect operation
Description: The chart shows the data element usage intensity of users per unprotect operation. It displays the top 10 data elements used by the top five users.
Type: Heat Map
Filter 1: protection.operation.keyword: Unprotect
Filter 2: Audit Index Logtypes
Configuration:
Index: pty_insight_*audit*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Terms
Field: protection.policy_user.keyword
Order by: Metric: Count
Order: Descending
Size: 5
Y-axis
Sub aggregation: Terms
Field: protection.dataelement.keyword
Order by: Metric:Count
Order: Descending
Size: 10
Server Activity of Older Audit Indices By Date
Description: The chart shows the daily count of all events by servers for specific time period from the old audit index.
Type: Line
Configuration:
Index: pty_insight_*audit_*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum interval: Day
Split series
Sub aggregation: Terms
Field: origin.hostname.keyword
Order by: Metric:Count
Order: Descending
Size: 50
Server Activity of Audit Index By Date
Description: The chart shows the daily count of all events by servers for specific time period from the audit index.
Type: Line
Configuration:
Index: pty_insight_analytics*audits_*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum interval: Day
Split series
Sub aggregation: Terms
Field: origin.hostname.keyword
Order by: Metric:Count
Order: Descending
Size: 50
Server Activity of Policy Index By Date
Description: The chart shows the daily count of all events by servers for specific time period from the policy index.
Type: Line
Configuration:
Index: pty_insight_analytics*policy_log_*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum interval: Day
Split series
Sub aggregation: Terms
Field: origin.hostname.keyword
Order by: Metric:Count
Order: Descending
Size: 50
Server Activity of Troubleshooting Index By Date
Description: The chart shows the daily count of all events by servers for specific time period from the troubleshooting index.
Type: Line
Configuration:
Index: pty_insight_analytics*troubleshooting_*
Metrics: Y-axis: Count
Buckets:
X-axis
Aggregation: Date Histogram
Field: origin.time_utc
Minimum interval: Day
Split series
Sub aggregation: Terms
Field: origin.hostname.keyword
Order by: Metric:Count
Order: Descending
Size: 50
Connectivity status
Description: This pie chart display connectivity status for the protectors.
Description: This table displays the policy deployment status and uniquely identified information for the data store, protector, process, platform, node, and so on.
Description: The trusted application deployment status that is displayed on the dashboard. This table uniquely identifies the data store, protector, process, platform, node, and so on.