Linux - Auditd
WidgetDescriptionType
Event Results

Hide Query

Show Query

Time Chart
Top 5 Users (Events)

Hide Query

Show Query

Table
Event Types Descriptions

Hide Query

Show Query

Table
Top 10 Exec Commands Displays a list of the top ten audited executive commands.

Hide Query

Show Query

Table
Event Types Breakdown

Hide Query

Show Query

Pie Chart
Number of Events (by host)

Hide Query

Show Query

Time Chart
Linux - General
WidgetDescriptionType
Number of Linux Hosts

Hide Query

Show Query

Gauge
Number of System Events

Hide Query

Show Query

Gauge
Number of Auditd Events

Hide Query

Show Query

Gauge
Number of User Modifications

Hide Query

Show Query

Gauge
Latest User Modifications

Hide Query

Show Query

Table
Events by Host

Hide Query

Show Query

Time Chart
Linux - SSH
WidgetDescriptionType
[ssh] Suspicious Activity

Hide Query

Show Query

Table
[ssh] Failed Source IPs Displays a list of failed SSH source IPs that have failed by user and limits results to the first 10 entries.

Hide Query

Show Query

Bar Chart
[ssh] Events by Host

Hide Query

Show Query

Time Chart
[ssh] Failed Login Attempts

Hide Query

Show Query

Gauge
Linux - Sudo
WidgetDescriptionType
[sudo] Top Commands

Hide Query

Show Query

Pie Chart
[sudo] Latest Events

Hide Query

Show Query

Table
[sudo] Number of Events

Hide Query

Show Query

Gauge
[sudo] Opened Sessions This describes recent instances of sudo being executed.

Hide Query

Show Query

Table
[sudo] Events by Host

Hide Query

Show Query

Time Chart