apache/http-server Dashboards
The Error Log Analysis dashboard provides comprehensive error monitoring and diagnostics through detailed log-based visualizations. This dashboard enables tracking of critical server errors, analysis of client-error patterns, and monitoring of error distributions across server instances.
The HTTP Errors dashboard presents detailed HTTP error analysis through status code-focused visualizations. This dashboard enables monitoring of client and server errors, tracking of error patterns by URL, and assessment of error distributions across web servers.
The IOC Matches for Client IP dashboard provides threat intelligence analysis through indicator-based visualizations. This dashboard enables tracking of threat actor activities, monitoring of malware patterns, and assessment of kill chain progression across client connections.
IOC matches for referer domain
The IOC Matches for Referer Domain dashboard presents domain-based threat analysis through comprehensive security visualizations. This dashboard enables identification of malicious domains, tracking of threat relationships, and analysis of threat actor patterns across referral traffic.
The Overview dashboard provides comprehensive web server performance metrics through integrated traffic visualizations. This dashboard enables monitoring of visitor patterns, tracking of server response metrics, and analysis of data transfer volumes across web services.
The Visitor Insights dashboard presents detailed visitor behavior analysis through geographic and traffic-based visualizations. This dashboard enables tracking of visitor origins, monitoring of referral sources, and detection of malicious traffic patterns across web properties.
Error log analysis
The Error Log Analysis dashboard provides comprehensive error monitoring and diagnostics through detailed log-based visualizations. This dashboard enables tracking of critical server errors, analysis of client-error patterns, and monitoring of error distributions across server instances.
| Widget | Description | Type |
|---|---|---|
Which are the top client IP addresses that appear in error log
events (var/log/apache2/error.log)
| Time Chart | |
List of error messages (from var/log/apache2/error.log) sorted by
greatest number of occurrences of each message. NB some error log
message types contain server/host specific information.
| Table | |
Volume of error logs by log type over time (from
var/log/apache2/error.log)
| Time Chart | |
The most common emerg,
crit or
alert error messages with
server name, error message and the number of instances of this
message (from var/log/apache2/error.log)
| Table | |
Which are the server names that appear in error log events
(var/log/apache2/error.log)
| Time Chart | |
Location of client IPs that are associated with error log events
of type emerg,
crit or
alert (from
var/log/apache2/error.log). Note - location of client IP does not
always correlate with actual physical location of user or system
| World Map |
HTTP errors
The HTTP Errors dashboard presents detailed HTTP error analysis through status code-focused visualizations. This dashboard enables monitoring of client and server errors, tracking of error patterns by URL, and assessment of error distributions across web servers.
| Widget | Description | Type |
|---|---|---|
Which client IPs are causing the most 4XX errors
| Time Chart | |
Volume of server and client errors over time
| Time Chart | |
The 5 URLs with the most 5XX errors over time
| Time Chart | |
The 5 URLs with the most 4XX errors over time
| Time Chart | |
Number of 4XX status codes by server
| Bar Chart | |
Number of 5XX status codes by server
| Bar Chart | |
Number of 4xx (client) and 5xx (server) errors
| Pie Chart | |
Which Client IPs are causing most 4XX errors with the specific
error code and description
| Table |
IOC matches for client IP
The IOC Matches for Client IP dashboard provides threat intelligence analysis through indicator-based visualizations. This dashboard enables tracking of threat actor activities, monitoring of malware patterns, and assessment of kill chain progression across client connections.
| Widget | Description | Type |
|---|---|---|
Location of client IP addresses present in IOC. Note - location of
client IP does not always correlate with actual physical location
of user or system
| World Map | |
Number of client IP IOC matches by confidence threshold over time
| Time Chart | |
Pie chart showing breakdown of threat types (linked to client IP)
| Pie Chart | |
Links client IP IOC labels to the different values of each label
| Sankey | |
Pie chart showing breakdown of threat actors (linked to client IP)
| Pie Chart | |
Pie chart showing breakdown of kill chain values (linked to client
IP)
| Pie Chart | |
Detailed information of all threats found in client IPs
| Table | |
Pie chart showing breakdown of malware types (linked to client IP)
| Pie Chart | |
| # All Details The table below shows details of all the threats found, irrespective of the threshold filter applied. Click on the various aspects of these results to drill down into the raw events | Note | |
Falcon LogScale includes an integration with CrowdStrike's Falcon
Intelligence to provide Falcon LogScale customers with a built-in
database of Indicators of Compromise (IOCs). Customers can search
their logs for matches against the IOC database and see relevant
threat information for each IOC found.
Find
out more. This dashboard takes the
client_ip field from both
Apache access and error logs and checks it against known IP
addresses in the IOC database with the
ioc:lookup() function.
| Note |
IOC matches for referer domain
The IOC Matches for Referer Domain dashboard presents domain-based threat analysis through comprehensive security visualizations. This dashboard enables identification of malicious domains, tracking of threat relationships, and analysis of threat actor patterns across referral traffic.
| Widget | Description | Type |
|---|---|---|
Location of client IP addresses present in IOC. Note - location of
client IP does not always correlate with actual physical location
of user or system
| World Map | |
Pie chart showing breakdown of threat types (linked to client IP)
| Pie Chart | |
Links client IP IOC labels to the different values of each label
| Sankey | |
Pie chart showing breakdown of threat actors (linked to client IP)
| Pie Chart | |
Pie chart showing breakdown of kill chain values (linked to client
IP)
| Pie Chart | |
Detailed information of all threats found in client IPs
| Table | |
Pie chart showing breakdown of malware types (linked to client IP)
| Pie Chart | |
| # All Details The table below shows details of all the threats found, irrespective of the threshold filter applied. Click on the various aspects of these results to drill down into the raw events | Note | |
Falcon LogScale includes an integration with CrowdStrike's Falcon
Intelligence to provide Falcon LogScale customers with a built-in
database of Indicators of Compromise (IOCs). Customers can search
their logs for matches against the IOC database and see relevant
threat information for each IOC found.
Find
out more. This dashboard extracts the
domain from the
referer field of the
Apache access logs and checks it against known domains in the IOC
database with the ioc:lookup() function.
| Note |
Overview
The Overview dashboard provides comprehensive web server performance metrics through integrated traffic visualizations. This dashboard enables monitoring of visitor patterns, tracking of server response metrics, and analysis of data transfer volumes across web services.
| Widget | Description | Type |
|---|---|---|
Breakdown of response volumes by type over time
| Time Chart | |
Number of unique client IPs visiting server(s)
| Time Chart | |
Location of client IPs. Note location of client IP does not always
correlate with actual physical location of user or system
| World Map | |
Total volume of data served by web server(s) over time
| Time Chart | |
Relative volume of each media type served - note media type is
determined from the URL
| Pie Chart | |
Requests received per second
| Time Chart | |
Volume of bytes served for each media type over time. Note - media
type is determined from the URL
| Time Chart | |
Total volume of data served by web server(s)
| Single Value | |
List of all web servers
| Table | |
Total number of unique client IPs visiting server(s)
| Single Value |
Visitor insights
The Visitor Insights dashboard presents detailed visitor behavior analysis through geographic and traffic-based visualizations. This dashboard enables tracking of visitor origins, monitoring of referral sources, and detection of malicious traffic patterns across web properties.
| Widget | Description | Type |
|---|---|---|
Location of client IPs. Note location of client IP does not always
correlate with actual physical location of user or system
| World Map | |
Top 10 user agents making any requests, irrespective of success or
error
| Table | |
Domains that exists in CrowdStrike's Falcon LogScale IOC database.
See the 'IOC matches for referer domain' dashboard for more
details
| Single Value | |
Most common URLs - counts only successful requests
| Table | |
The sites referring visitors to your sites
| Pie Chart | |
The sites referring visitors to your sites
| Time Chart | |
Client IPs that exists in CrowdStrike's Falcon LogScale IOC
database. See the 'IOC matches for client IP' dashboard for more
details
| Single Value |