Linux - Auditd
WidgetDescriptionType
Event Results Displays a chart of audited event results.

Show Query

Time Chart
Top 5 Users (Events) Displays a table of the top 5 system users and events using audited event data.

Show Query

Table
Event Types Descriptions Displays a table of event type descriptions using audit data.

Show Query

Table
Top 10 Exec Commands Displays a list of the top ten audited executive commands.

Show Query

Table
Event Types Breakdown Provides a pie chart of event types using audit data.

Show Query

Pie Chart
Number of Events (by host) Displays a chart of the number of events by host and limits results to the first 10 entries.

Show Query

Time Chart
Linux - General
WidgetDescriptionType
Number of Linux Hosts Displays the total number of Linux hosts.

Show Query

Gauge
Number of System Events Displays the number of system events.

Show Query

Gauge
Number of Auditd Events Displays the number of audited events for a given user.

Show Query

Gauge
Number of User Modifications Displays the number of user modifications from audit data.

Show Query

Gauge
Latest User Modifications Displays a table of a user's latest modifications using audit data.

Show Query

Table
Events by Host Displays a chart of events by host.

Show Query

Time Chart
Linux - SSH
WidgetDescriptionType
[ssh] Suspicious Activity Displays a table of suspicious SSH login activity like unknown or invalid users.

Show Query

Table
[ssh] Failed Source IPs Displays a list of failed SSH source IPs that have failed by user and limits results to the first 10 entries.

Show Query

Bar Chart
[ssh] Events by Host Displays a chart of the top 10 SSH events by host.

Show Query

Time Chart
[ssh] Failed Login Attempts Displays a list of failed SSH login attempts.

Show Query

Gauge
Linux - Sudo
WidgetDescriptionType
[sudo] Top Commands Displays a chart of the top Sudo commands used.

Show Query

Pie Chart
[sudo] Latest Events Displays a table of the latest sudo events and associated data (timestamp, host, PID, etc.)

Show Query

Table
[sudo] Number of Events Displays the number of sudo events

Show Query

Gauge
[sudo] Opened Sessions This describes recent instances of sudo being executed.

Show Query

Table
[sudo] Events by Host Displays a chart of sudo events by host over time.

Show Query

Time Chart