---
title: "Security dashboard"
canonical: "https://docs.aryaka.com/space/KNOW/123895836/Security%20dashboard"
format: markdown
---
The Security dashboard displays a summary of security data that is collected as network traffic is processed by the various Aryaka security engines. This traffic data is originally written to the security log, then parsed, and used to produce the graphs and other components included on the Security dashboard. This topic describes the statistics displayed on the Insights > Dashboards > Security page. What would you like to do? If you are trying to achieve the following goals, use the associated components of the Security dashboard: I want to identify risks to my network: Summary tiles —View the Flows Blocked and Requests Blocked tiles for an at-a-glance understanding of the amount of traffic blocked by your security policies. Click these tiles to view the  Security > Monitor  page where you can view blocks for each security engine and access security logs.  Security graphs and tables —View the SaaS applications, SaaS application categories, and reputation scores (SaaS application, web, and DNS) that are most common in the traffic inspected by the security engines. You can also view any security incidents that have occurred and your top risky users and hosts according to web reputation score. Click the metrics in these graphs to view associated  security logs . I want to verify that my security policies are working as expected: Security graphs and tables —View the applications, domains, and web categories that were permitted by your security policies as well as the applications, users, web categories, DNS categories, sites, domains, and hosts that were blocked by your security policies. You can also view the amount of traffic blocked by each security engine and the amount of traffic assigned each verdict by the three IPS security engines. Click the metrics in these graphs to view associated  security logs . I want to ensure that my services are properly implemented: Summary tiles —View the Sites, Regions, Zones, and Users tiles for a high-level understanding of your current network security configuration. Click these tiles if you need to adjust the associated configuration. Security dashboard components The Security dashboard displays a series of summary tiles and graphs and tables to provide an overview of your security posture. These components are described in the sections that follow. Summary tiles The Security dashboard includes summary tiles that display current data for the following metrics: Sites—View the number of sites that are licensed for the various Aryaka security offerings (FWaaS, NGFW-SWG, IPS, and Anti-Malware). Click this tile to view the  Sites  page. Regions—View the number of Private Access regions that are licensed for the various Aryaka security offerings (FWaaS, NGFW-SWG, IPS, and Anti-Malware). Click this tile to display the  Universal ZTNA > Private Access  page. Zones—View the total number of zones configured in your Aryaka network. There are two types of zones that can be configured: segments (also known as a VPN zones) and DMZ zones (can only be configured for sites with an ANAP). Click this tile to display the  Security > Settings > Zones  page. Users—View the total number of unique users logged in during the selected time range from all ANAPs or POPs that have NGFW-SWG enabled. Flows Blocked—View the number of flows that were denied as the result of any security rule or feature being applied to the flow. Click this tile to display the  Security > Monitor  page where you can view the number of flows denied for each individual security engine in the Engine Sequencing diagram.  Requests Blocked—View the number of HTTP requests that were denied as the result of any security rule or feature being applied to the flow.   Click this tile to display the  Security > Monitor  page where you can view the number of HTTP requests denied for each individual security engine in the Engine Sequencing diagram. Incidents—View the number of security incidents that have occurred during the selected time period. Note that this tile only appears for users whose organization has purchased AI>Observe. Click this tile to view your organization's Home page on the cloud-based, AI-driven Sequretek Percept XDR platform (at  https://xdrp.sequretek.com ). Sequretek powers the AI>Observe offering. Security graphs and tables The Security Home page displays security statistics in various graphs and tables. The individual graphs and tables are described in the sections that follow. Incidents by Severity The Incidents by Severity pane only appears for users whose organization has purchased AI>Observe. It contains a donut graph and a table view that displays the total number of security incidents encountered and the number of incidents in each of the following color-coded severity categories: Informational Low Medium High Critical It also contains a View Details icon that links to your organization's Home page on the cloud-based, AI-driven Sequretek Percept XDR platform (at  https://xdrp.sequretek.com ). Sequretek powers the AI>Observe offering. Top SaaS Apps The Top SaaS Apps pane contains a bar graph and a table view that displays the following: Up to 10 SaaS applications that were classified by security rules. The total number of HTTP requests classified for each SaaS application. The percentage of HTTP requests classified for each SaaS application (graph view only). For each SaaS application, the distribution of the top clients (up to four) for which the requests were classified (graph view only). For each client, the number of HTTP requests classified for the SaaS application (graph view only). For each client, the percentage of HTTP requests classified for the SaaS application (graph view only). Use the drop-down list to view this data for sanctioned, unsanctioned, unclassified, or all applications. Top Permitted SaaS Apps The Top Permitted SaaS Apps pane contains a bar graph and a table view that displays the following: Up to 10 SaaS applications that were permitted by security rules. The total number of HTTP requests permitted for each SaaS application. The percentage of HTTP requests permitted for each SaaS application (graph view only). For each SaaS application, the distribution of the top clients (up to four) for which the requests were permitted (graph view only). For each client, the number of HTTP requests permitted for the SaaS application (graph view only). For each client, the percentage of HTTP requests permitted for the SaaS application (graph view only). Use the drop-down list to view this data for sanctioned, unsanctioned, unclassified, or all applications.  Top Blocked SaaS Apps The Top Blocked SaaS Apps pane contains a bar graph and a table view that displays the following: Up to 10 SaaS applications that were blocked by security rules. The total number of HTTP requests blocked for each SaaS application. The percentage of HTTP requests blocked for each SaaS application (graph view only). For each SaaS application, the distribution of the top clients (up to four) for which the requests were blocked (graph view only). For each client, the number of HTTP requests blocked for the SaaS application (graph view only). For each client, the percentage of HTTP requests blocked for the SaaS application (graph view only). Use the drop-down list to view this data for sanctioned, unsanctioned, unclassified, or all applications.  Top SaaS App Categories The Top SaaS App Categories pane contains a bar graph and a table view that displays the following: Up to 10 SaaS application categories that were classified by security rules. The total number of HTTP requests classified for each SaaS application category. The percentage of HTTP requests classified for each SaaS application category (graph view only). For each SaaS application category, the distribution of the top clients (up to four) for which the requests were classified (graph view only). For each client, the number of HTTP requests classified for the SaaS application category (graph view only). For each client, the percentage of HTTP requests classified for the SaaS application category (graph view only). SaaS App Reputation Scores SaaS application reputation scores are relative number ranges that categorize the risk associated with SaaS application HTTP requests. The risks and numeric ranges appear in the following table: Risk Range Unknown 0 High 1-20 Suspicious 21-40 Moderate 41-60 Low 61-80 Trustworthy 81-100 The SaaS App Reputation Scores pane contains a donut graph and table view that displays the following: The total number of HTTP requests processed by the SaaS Apps Access Control security engine (graph view only). The total number of HTTP requests processed by the SaaS Apps Access Control security engine for each of the risks (moderate, trustworthy, and so on). The number of HTTP requests permitted and denied by the SaaS Apps Access Control security engine for each of the risks. The percentage of the total HTTP requests processed by the SaaS Apps Access Control security engine for each of the risks (graph view only). Blocks by Security Engines The Blocks by Security Engines pane contains a donut graph and table view that displays the following: Security engines responsible for blocking either the flows or HTTP requests. Total number of flows or HTTP requests blocked by  all  listed security engines (graph view only). Total number of flows or HTTP requests blocked by  each  listed security engine. Percentage of flows or HTTP requests blocked by each security engine. Web Reputation Scores Web reputation scores are relative number ranges that categorize the risk associated with flows (using the domain reputation score) or HTTP requests (using the URL reputation score). The risks and numeric ranges appear in the following table: Risk Range Unknown 0 High 1-20 Suspicious 21-40 Moderate 41-60 Low 61-80 Trustworthy 81-100 The Web Reputation Scores pane contains a donut graph and table view that displays the following: The total number of flows (inbound  and  outbound) or HTTP requests processed by the NGFW (for flows) or the SWG (for HTTP requests) security engines (graph view only). The total number of flows or HTTP requests processed by the corresponding security engine for each of the risks (moderate, trustworthy, and so on). The number of flows permitted and denied by the security engine for each of the risks. The percentage of the total flows processed by the security engine for each of the risks (graph view only). Top Blocked Users The Top Blocked Users pane contains a table that displays the following: Up to 10 users who have been blocked by security rules identified by their email addresses. The total number of times they were blocked. The security engines that blocked them (for example, Secure Web Gateway). The number of times they were blocked by each security engine. Top Blocked Web Categories The Top Blocked Web Categories pane contains a bar graph and a table view that displays the following: Up to 10 web categories that have been blocked by security rules. The number of flows or HTTP requests that were blocked for each category. LAN-Side Basic IPS Verdicts The LAN-Side Basic Verdicts pane contains a donut graph and a table view that displays the following: The total number of verdicts that have been enforced by LAN-Side Basic IPS rules on your LAN traffic (graph view only). The number of verdicts—and the corresponding action that was taken—for each of the following verdict types: Pass Drop Reject Alert Unknown The percentage of the total number of verdicts for each graphed verdict type (graph view only). Advanced IPS Verdicts The Advanced IPS Verdicts pane contains a donut graph and a table view that displays the following: The total number of verdicts that that have been enforced by Advanced IPS rules, which determine if SSL inspection is required on your outbound traffic by inspecting it for signatures that indicate a potential threat (graph view only). The number of verdicts—and the corresponding action that was taken—for each of the following verdict types: Pass Drop Reject Alert Unknown The percentage of the total number of verdicts for each graphed verdict type (graph view only). WAN-Side Basic IPS Verdicts The WAN-Side Basic Verdicts pane contains a donut graph and a table view that displays the following: The total number of verdicts that have been enforced by WAN-Side Basic IPS rules on your WAN traffic (graph view only). The number of verdicts—and the corresponding action that was taken—for each of the following verdict types: Pass Drop Reject Alert Unknown The percentage of the total number of verdicts for each graphed verdict type (graph view only). Top Blocked DNS Categories The Top Blocked DNS Categories pane contains a bar graph that displays the following: Up to 10 DNS categories that have been blocked by security rules. The number of flows that were blocked for each category. Top Blocked Sites The Top Blocked Sites pane contains a contains a bar graph and a table view that displays the following: Up to 10 sites that have been blocked by security rules. The number of flows that were blocked for each site. DNS Reputation Scores DNS scores are relative number ranges that categorize the risk associated with flows (using the domain reputation score). The risks and numeric ranges appear in the following table: Risk Range Unknown 0 High 1-20 Suspicious 21-40 Moderate 41-60 Low 61-80 Trustworthy 81-100 The DNS Reputation Scores pane contains a donut graph that displays the following: The total number of flows (inbound  and  outbound) processed by the DNS Filtering security engine. The total number of flows processed by the DNS Filtering security engine for each of the risks (moderate, trustworthy, and so on). The percentage of the total flows processed by the DNS Filtering security engine for each of the risks. Top Permitted Applications The Top Permitted Applications pane contains a bar graph and a table view that displays the following: Up to 10 applications that were permitted by security rules. The total number of flows or HTTP requests permitted for each application. The percentage of flows or HTTP requests permitted for each application (graph view only). For each application, the distribution of the top clients (up to four) for which the flows or requests were permitted (graph view only). For each client, the number of flows or HTTP requests permitted for the application (graph view only). For each client, the percentage of flows or HTTP requests permitted for the application (graph view only). Top Permitted Domains The Top Permitted Domains pane contains a bar graph and a table view that displays the following: Up to 10 domains that were permitted by security rules. The total number of flows or HTTP requests permitted for each domain. The percentage of flows or HTTP requests permitted for each domain (graph view only). For each domain, the distribution of the top clients (up to four) for which the flows or requests were permitted (graph view only). For each client, the number of flows or HTTP requests permitted for the domain (graph view only). For each client, the percentage of flows or HTTP requests permitted for the domain (graph view only). Top Permitted Web Categories The Top Permitted Web Categories pane contains a bar graph and a table view that displays the following: Up to 10 web categories that were permitted by security rules. The total number of flows or HTTP requests permitted for each web category. The percentage of flows or HTTP requests permitted for each web category (graph view only). For each web category, the distribution of the top clients (up to four) for which the flows or requests were permitted (graph view only). For each client, the number of flows or HTTP requests permitted for the web category (graph view only). For each client, the percentage of flows or HTTP requests permitted for the web category (graph view only). Top Blocked Applications The Top Blocked Applications pane contains a bar graph and a table view that displays the following: Up to 10 applications that were blocked by security rules. The total number of flows or HTTP requests blocked for each application. The percentage of flows or HTTP requests blocked for each application (graph view only). For each application, the distribution of the top clients (up to four) for which the flows or requests were blocked (graph view only). For each client, the number of flows or HTTP requests blocked for the application (graph view only). For each client, the percentage of flows or HTTP requests blocked for the application (graph view only). Top Blocked Domains The Top Blocked Domains pane contains a bar graph and table view that displays the following: Up to 10 domains that were blocked by security rules. The total number of flows or HTTP requests blocked for each domain. The percentage of flows or HTTP requests blocked for each domain (graph view only). For each domain, the distribution of the top clients (up to four) for which the flows or requests were blocked (graph view only). For each client, the number of flows or HTTP requests blocked for the domain (graph view only). For each client, the percentage of flows or HTTP requests blocked for the domain (graph view only). Top Blocked Hosts The Top Blocked Hosts pane contains a table that displays the following: Up to 10 hosts that were blocked by security rules. The total number of flows that were blocked for each host. For each host, the distribution of the top security engines (up to three) that blocked flows. Click the host or the total number of blocks to view all security logs where the selected host was blocked.   Click the number of blocks for a securit engine to view all security logs where the selected host was blocked by the selected security engine.  Top Risky Hosts by Web Reputation The Top Risky Hosts by Web Reputation pane contains a bar graph and a table view that displays the following: Up to 10 hosts for which traffic with a web reputation score of 20 or less was permitted by security rules. The total number of flows or HTTP requests with a web reputation score of 20 or less that were permitted for each host. The percentage of flows or HTTP requests with a web reputation score of 20 or less that were permitted for each host (graph view only). Top Risky Users by Web Reputation The Top Risky Users by Web Reputation pane contains a bar graph and a table view that displays the following: Up to 10 users for which traffic with a web reputation score of 20 or less was permitted by security rules. The total number of flows or HTTP requests with a web reputation score of 20 or less that were permitted for each user. The percentage of flows or HTTP requests with a web reputation score of 20 or less that were permitted for each user. (graph view only).  In this topic Related topics View security logs View and manage alerts AI>Observe overview