Linux - Auditd
WidgetDescriptionType
Event Results Displays a chart of audited event results.

Hide Query

Show Query

Time Chart
Top 5 Users (Events) Displays a table of the top 5 system users and events using audited event data.

Hide Query

Show Query

Table
Event Types Descriptions

Hide Query

Show Query

Table
Top 10 Exec Commands Displays a list of the top ten audited executive commands.

Hide Query

Show Query

Table
Event Types Breakdown Provides a pie chart of event types using audit data.

Hide Query

Show Query

Pie Chart
Number of Events (by host) Displays a chart of the number of events by host and limits results to the first 10 entries.

Hide Query

Show Query

Time Chart
Linux - General
WidgetDescriptionType
Number of Linux Hosts Displays the total number of Linux hosts.

Hide Query

Show Query

Gauge
Number of System Events

Hide Query

Show Query

Gauge
Number of Auditd Events Displays the number of audited events for a given user.

Hide Query

Show Query

Gauge
Number of User Modifications Displays the number of user modifications from audit data.

Hide Query

Show Query

Gauge
Latest User Modifications Displays a table of a user's latest modifications using audit data.

Hide Query

Show Query

Table
Events by Host Displays a chart of events by host.

Hide Query

Show Query

Time Chart
Linux - SSH
WidgetDescriptionType
[ssh] Suspicious Activity Displays a table of suspicious SSH login activity like unknown or invalid users.

Hide Query

Show Query

Table
[ssh] Failed Source IPs Displays a list of failed SSH source IPs that have failed by user and limits results to the first 10 entries.

Hide Query

Show Query

Bar Chart
[ssh] Events by Host Displays a chart of the top 10 SSH events by host.

Hide Query

Show Query

Time Chart
[ssh] Failed Login Attempts Displays a list of failed SSH login attempts.

Hide Query

Show Query

Gauge
Linux - Sudo
WidgetDescriptionType
[sudo] Top Commands Displays a chart of the top Sudo commands used.

Hide Query

Show Query

Pie Chart
[sudo] Latest Events Displays a table of the latest sudo events and associated data (timestamp, host, PID, etc.)

Hide Query

Show Query

Table
[sudo] Number of Events

Hide Query

Show Query

Gauge
[sudo] Opened Sessions This describes recent instances of sudo being executed.

Hide Query

Show Query

Table
[sudo] Events by Host

Hide Query

Show Query

Time Chart