Environment Health Dashboard
Copy link

The Environment Health Dashboard gives you a consolidated view of data collection health across your environment. By surfacing the current state of your data sources in a single place, the dashboard helps you quickly identify issues and reduce the time it takes to investigate and respond to collection problems.

The dashboard is organized into modular sections, each providing a different view of your data source health. If no data is available for a data source, the dashboard displays an empty state. If an object has not been set up yet, the empty state includes a link to the relevant setup documentation.

The dashboard reflects a point-in-time snapshot of your environment. Data is refreshed every 30 minutes and the dashboard does not display historical trends.

ℹ️

Available data sources

The initial release of the dashboard includes data and visuals for Agents, Collectors, Event Sources, Honeypots, and Data Exporters. Support for Network Sensors, Orchestrators, and Scan Engines will be added in a future release.

KPI bar
Copy link

The KPI bar displays key counts for the current state of your data sources at a glance. For Agents, this includes the number of online, offline, stale, and total agents. For other data source types, state information is shown as a string value.

Selecting a KPI takes you to the corresponding page in the Command Platform, filtered to show objects in that state.

State bar chart
Copy link

The state bar chart gives you the same current-state information as the KPI bar, presented as a visual snapshot. Hovering over a bar shows the number of data sources in that state.

Selecting a bar takes you to the corresponding page in the Command Platform, filtered to show objects in that state.

Issue feed
Copy link

The issue feed lists known issues for the selected data source as of the last data sync. Issues are sorted by severity.

Each issue includes:

  • Issue - A description of the problem
  • Event time - When the issue was recorded
  • Severity - The severity level of the issue
  • Last active - When the issue was last active

If more than 5 issues exist, you can expand the card to a full-screen view to see all of them. You can also open the relevant product documentation directly from the issue feed.

To open the relevant product documentation for an error:

  1. Select the ellipsis in the Actions column.
  2. Select Help Documentation.

If no issues are present, the issue feed displays an empty state.

Resourcing table
Copy link

The resourcing table shows capacity and metadata that may indicate risk for the selected data source. For Collectors, this includes:

  • Memory used
  • Maximum memory
  • CPU usage percentage
  • Storage used
  • Event sources used
  • Maximum event sources

For other data source types, state information is displayed as a string value.

In the Collector resourcing card, the Event Source column links to the Event Sources page, filtered by the selected Collector.

Inactive event sources
Copy link

The inactive event sources card shows event sources that are either in a Stopped state or have not been active in more than 24 hours. Each entry includes the event source state and last active timestamp.

If more than 5 inactive event sources exist, you can expand the card to a full-screen view to see all of them.

Export a report
Copy link

You can export the dashboard data as a PDF or HTML file.

To export the dashboard:

  1. Select Create Report at the top of the page.