• Error log analysis

    The Error Log Analysis dashboard provides comprehensive error monitoring and diagnostics through detailed log-based visualizations. This dashboard enables tracking of critical server errors, analysis of client-error patterns, and monitoring of error distributions across server instances.

  • HTTP errors

    The HTTP Errors dashboard presents detailed HTTP error analysis through status code-focused visualizations. This dashboard enables monitoring of client and server errors, tracking of error patterns by URL, and assessment of error distributions across web servers.

  • IOC matches for client IP

    The IOC Matches for Client IP dashboard provides threat intelligence analysis through indicator-based visualizations. This dashboard enables tracking of threat actor activities, monitoring of malware patterns, and assessment of kill chain progression across client connections.

  • IOC matches for referer domain

    The IOC Matches for Referer Domain dashboard presents domain-based threat analysis through comprehensive security visualizations. This dashboard enables identification of malicious domains, tracking of threat relationships, and analysis of threat actor patterns across referral traffic.

  • Overview

    The Overview dashboard provides comprehensive web server performance metrics through integrated traffic visualizations. This dashboard enables monitoring of visitor patterns, tracking of server response metrics, and analysis of data transfer volumes across web services.

  • Visitor insights

    The Visitor Insights dashboard presents detailed visitor behavior analysis through geographic and traffic-based visualizations. This dashboard enables tracking of visitor origins, monitoring of referral sources, and detection of malicious traffic patterns across web properties.

Error log analysis

The Error Log Analysis dashboard provides comprehensive error monitoring and diagnostics through detailed log-based visualizations. This dashboard enables tracking of critical server errors, analysis of client-error patterns, and monitoring of error distributions across server instances.

WidgetDescriptionType
Top 5 clients associated with error events Which are the top client IP addresses that appear in error log events (var/log/apache2/error.log)

Hide Query

Show Query

Time Chart
Top error messages List of error messages (from var/log/apache2/error.log) sorted by greatest number of occurrences of each message. NB some error log message types contain server/host specific information.

Hide Query

Show Query

Table
Error log levels over time Volume of error logs by log type over time (from var/log/apache2/error.log)

Hide Query

Show Query

Time Chart
Critical errors The most common emerg, crit or alert error messages with server name, error message and the number of instances of this message (from var/log/apache2/error.log)

Hide Query

Show Query

Table
Top 5 servers that are associated with error events Which are the server names that appear in error log events (var/log/apache2/error.log)

Hide Query

Show Query

Time Chart
Client locations associated with critical errors Location of client IPs that are associated with error log events of type emerg, crit or alert (from var/log/apache2/error.log). Note - location of client IP does not always correlate with actual physical location of user or system

Hide Query

Show Query

World Map
HTTP errors

The HTTP Errors dashboard presents detailed HTTP error analysis through status code-focused visualizations. This dashboard enables monitoring of client and server errors, tracking of error patterns by URL, and assessment of error distributions across web servers.

WidgetDescriptionType
Top clients causing 4xx errors Which client IPs are causing the most 4XX errors

Hide Query

Show Query

Time Chart
HTTP errors over time Volume of server and client errors over time

Hide Query

Show Query

Time Chart
Top URLs with 5xx errors The 5 URLs with the most 5XX errors over time

Hide Query

Show Query

Time Chart
Top URLs with 4xx errors The 5 URLs with the most 4XX errors over time

Hide Query

Show Query

Time Chart
4xx codes by server Number of 4XX status codes by server

Hide Query

Show Query

Bar Chart
5xx codes by server Number of 5XX status codes by server

Hide Query

Show Query

Bar Chart
Client (4xx) and server (5xx) errors Number of 4xx (client) and 5xx (server) errors

Hide Query

Show Query

Pie Chart
Clients with specific 4xx errors Which Client IPs are causing most 4XX errors with the specific error code and description

Hide Query

Show Query

Table
IOC matches for client IP

The IOC Matches for Client IP dashboard provides threat intelligence analysis through indicator-based visualizations. This dashboard enables tracking of threat actor activities, monitoring of malware patterns, and assessment of kill chain progression across client connections.

WidgetDescriptionType
IOC geolocation Location of client IP addresses present in IOC. Note - location of client IP does not always correlate with actual physical location of user or system

Hide Query

Show Query

World Map
Threat trends Number of client IP IOC matches by confidence threshold over time

Hide Query

Show Query

Time Chart
Threat types Pie chart showing breakdown of threat types (linked to client IP)

Hide Query

Show Query

Pie Chart
Threat relationships Links client IP IOC labels to the different values of each label

Hide Query

Show Query

Sankey
Actors Pie chart showing breakdown of threat actors (linked to client IP)

Hide Query

Show Query

Pie Chart
Kill chains Pie chart showing breakdown of kill chain values (linked to client IP)

Hide Query

Show Query

Pie Chart
All threat details Detailed information of all threats found in client IPs

Hide Query

Show Query

Table
Malware Pie chart showing breakdown of malware types (linked to client IP)

Hide Query

Show Query

Pie Chart
note-1624965575450 # All Details The table below shows details of all the threats found, irrespective of the threshold filter applied. Click on the various aspects of these results to drill down into the raw events Note
Introduction to indicators of compromise (IOC) dashboard Falcon LogScale includes an integration with CrowdStrike's Falcon Intelligence to provide Falcon LogScale customers with a built-in database of Indicators of Compromise (IOCs). Customers can search their logs for matches against the IOC database and see relevant threat information for each IOC found. Find out more. This dashboard takes the client_ip field from both Apache access and error logs and checks it against known IP addresses in the IOC database with the ioc:lookup() function. Note
IOC matches for referer domain

The IOC Matches for Referer Domain dashboard presents domain-based threat analysis through comprehensive security visualizations. This dashboard enables identification of malicious domains, tracking of threat relationships, and analysis of threat actor patterns across referral traffic.

WidgetDescriptionType
IOC geolocation Location of client IP addresses present in IOC. Note - location of client IP does not always correlate with actual physical location of user or system

Hide Query

Show Query

World Map
Threat types Pie chart showing breakdown of threat types (linked to client IP)

Hide Query

Show Query

Pie Chart
Threat relationships Links client IP IOC labels to the different values of each label

Hide Query

Show Query

Sankey
Actors Pie chart showing breakdown of threat actors (linked to client IP)

Hide Query

Show Query

Pie Chart
Kill chains Pie chart showing breakdown of kill chain values (linked to client IP)

Hide Query

Show Query

Pie Chart
All threat details Detailed information of all threats found in client IPs

Hide Query

Show Query

Table
Malware Pie chart showing breakdown of malware types (linked to client IP)

Hide Query

Show Query

Pie Chart
note-1624965575450 # All Details The table below shows details of all the threats found, irrespective of the threshold filter applied. Click on the various aspects of these results to drill down into the raw events Note
Introduction to indicators of compromise (IOC) dashboard Falcon LogScale includes an integration with CrowdStrike's Falcon Intelligence to provide Falcon LogScale customers with a built-in database of Indicators of Compromise (IOCs). Customers can search their logs for matches against the IOC database and see relevant threat information for each IOC found. Find out more. This dashboard extracts the domain from the referer field of the Apache access logs and checks it against known domains in the IOC database with the ioc:lookup() function. Note
Overview

The Overview dashboard provides comprehensive web server performance metrics through integrated traffic visualizations. This dashboard enables monitoring of visitor patterns, tracking of server response metrics, and analysis of data transfer volumes across web services.

WidgetDescriptionType
Responses over time Breakdown of response volumes by type over time

Hide Query

Show Query

Time Chart
Unique visitors Number of unique client IPs visiting server(s)

Hide Query

Show Query

Time Chart
World map of visitor locations Location of client IPs. Note location of client IP does not always correlate with actual physical location of user or system

Hide Query

Show Query

World Map
Bytes served over time Total volume of data served by web server(s) over time

Hide Query

Show Query

Time Chart
Bytes served by media type Relative volume of each media type served - note media type is determined from the URL

Hide Query

Show Query

Pie Chart
Requests per second for each server Requests received per second

Hide Query

Show Query

Time Chart
Bytes served by media type over time Volume of bytes served for each media type over time. Note - media type is determined from the URL

Hide Query

Show Query

Time Chart
Bytes served Total volume of data served by web server(s)

Hide Query

Show Query

Single Value
Web servers List of all web servers

Hide Query

Show Query

Table
Total visitors Total number of unique client IPs visiting server(s)

Hide Query

Show Query

Single Value
Visitor insights

The Visitor Insights dashboard presents detailed visitor behavior analysis through geographic and traffic-based visualizations. This dashboard enables tracking of visitor origins, monitoring of referral sources, and detection of malicious traffic patterns across web properties.

WidgetDescriptionType
Worldmap of visitor location Location of client IPs. Note location of client IP does not always correlate with actual physical location of user or system

Hide Query

Show Query

World Map
Top user agents Top 10 user agents making any requests, irrespective of success or error

Hide Query

Show Query

Table
Malicious referer domains Domains that exists in CrowdStrike's Falcon LogScale IOC database. See the 'IOC matches for referer domain' dashboard for more details

Hide Query

Show Query

Single Value
Top URLs Most common URLs - counts only successful requests

Hide Query

Show Query

Table
Top referers The sites referring visitors to your sites

Hide Query

Show Query

Pie Chart
Top referers over time The sites referring visitors to your sites

Hide Query

Show Query

Time Chart
Malicious client IPs Client IPs that exists in CrowdStrike's Falcon LogScale IOC database. See the 'IOC matches for client IP' dashboard for more details

Hide Query

Show Query

Single Value