---
title: "Monitor security"
canonical: "https://docs.aryaka.com/space/KNOW/39452841/Monitor%20security"
format: markdown
---
The Security > Monitor page enables you to view the overall usage of the security engines that determine whether to permit or deny network traffic based on your  configured security rules . If it is not already open, complete the following procedure to view the Security > Monitor page: To view the Security > Monitor page Log in to MyAryaka. The Home page appears. Click  Security  >  Monitor  in the left navigation pane. The Security: < siteName > page appears and displays the following sections: Filter Engine Sequencing diagram Tables and graphs Quicklink toolbar Click the  Scope  drop-down list and select one of the following options to filter the graphs displayed on the page: Global—Displays data for all sites and private access nodes.  All Sites—Displays data for all sites.   All Nodes—Displays data for all private access nodes. A specific site—Displays data for only the selected site. A specific node—Displays data for only the selected private access node. This topic describes the components of the Security > Monitor page.  The filter and graph features described here are used on subsequent pages as you click security engines or graph statistics to drill down into more specific details.  Filter The filter pane contains the following components that allow you to select the criteria that determines the graph details that appear on the page.  Component Description Time field Determines the period for which to monitor and graph the traffic for the selected scope. Each time period has an associated data interval defined for it. For example, if you select the Last 24 Hours time period, the associated data interval is 1 minute, which means a sample is taken and graphed every minute for a 24 hour period. Select one of the following time period/data interval pairs to graph the selected site's traffic: Last 1 Hour (1 minute) Last 4 Hours (1 minute) Last 8 Hours (1 minute) Last 24 Hours (1 minute) Last 7 Days (30 minutes) Last 30 days (30 minutes) Last Day (1 minute) Last Week (30 minutes) Last Month (30 minutes) Current Month (30 minutes) Custom (varies per custom time period defined) Note:  Last Day is different from Last 24 Hours. The Last 24 Hours plots graph with traffic collected in the last 24 hours. Last Day plots the traffic during the last calendar day. Similarly, Last Month plots the traffic during the last calendar month, and so on. Current Month plots the traffic during the current calendar month. You can select a custom time, date, and year going as far back as five years. Apply button Saves and applies your filter selections to the page's graphs. Engine Sequencing diagram The Engine Sequencing diagram displays the security engines in the order in which they receive and inspect traffic. The diagram displays the sequence of engines for outbound traffic by default, but you can change the display option at the top of the diagram to view the sequence for inbound traffic.  The following graphic (click to enlarge) shows an example of the outbound engine sequence: The red values displayed for each security engine indicate the number of flows that were dropped or denied by the engine over the selected time period. Click a security engine to view its corresponding monitor page.  Although you can select a specific scope for which to view the Security > Monitor page, the Engine Sequencing diagram displays  all  of the following security engines, even if they are not all enabled for the selected scope:  LAN-side basic IPS WAN Routing and Basic Firewall Interzone Firewall Internet Routing Domain Reputation Next Generation Firewall  (NGFW) DNS Filtering SaaS Apps Access Control URL Reputation Secure Web Gateway  (SWG) Data Loss Prevention (DLP) Anti-Malware Advanced IPS Tenant Restriction WAN-side Basic IPS  (inbound view only) Click a linked security engine to view its monitor page. Graph elements The graphs section displays a series of graphs based on the selections made in the filter fields. Each graph can include the following components, depending on the type of graph displayed: A title that indicates what data is being presented. An Expand icon that displays the graph fitted in the full page width. When expanded, the icon toggles to display the Collapse icon that displays the graph in its original width. An Options icon that allows you to download the graph to your default download directory as a PDF, CSV, or image (PNG) file. Display options that control the data presentation. The left option is displayed by default when the page or data is loaded. The option displayed currently has a white icon on a gray background. The following display options are available, though not all graphs include all options: Line—Displays two or more data points, with adjacent data points connected by a straight line. This component is used to represent the volume of data per second for the traffic statistic being plotted. Line graphs are also know as time series graphs. Click a category in the legend to hide or show the corresponding line in the graph. At least one category must remain selected. Hidden categories are represented by a white outlined box and displayed categories use a solid color. Hover over the graph to display the value of each statistic plotted on the graph at the corresponding time. Click, drag, and release to select a smaller window of time to display. This custom time selection now applies to all graphs on MyAryaka. After you select a custom time period, it is retained until you click the Reset icon in the Filter pane. Table—Displays the data points in rows and columns. Donut—Displays the relative total for each data category during the selected time period. Hover over a section of the graph to display the value of each plotted statistic. The Data Interval field displays the time period between each sample plotted on the graph. The interval is determined by your selection in the Time filter. Included graphs The sections that follow describe each of the graphs included on the Security > Monitor page. Outgoing Flows This graph can be viewed as a time series (default) or as a table. It displays the total number of flows, the number of permitted flows, and the number of denied flows from the selected scope over the selected time period. A  flow  is a series of communications between two network endpoints from the time a connection is established until it is terminated.  Incoming Flows This graph can be viewed as a time series (default) or table and displays the total number of flows, the number of permitted flows, and the number of denied flows to the selected scope over the selected time period. A  flow  is a series of communications between two network endpoints from the time a connection is established until it is terminated.  HTTP Requests This graph can be viewed as a time series (default) or table and displays the total number of HTTP requests, the number of permitted HTTP requests, and the number of denied HTTP requests for the selected scope over the selected time period. DNS Requests This graph can be viewed as a time series (default) or table and displays the total number of DNS requests, the number of permitted DNS requests, and the number of denied DNS requests for the selected scope over the selected time period. DNS Responses This graph can be viewed as a time series (default) or table and displays the total number of DNS responses, the number of permitted DNS responses, and the number of denied DNS responses for the selected scope over the selected time period. Domain Scores This graph can be viewed as a donut graph (default) or table and displays the total number of flows for each of the following domain reputation score categories: Trustworthy Low Risk Moderate Risk Suspicious High Risk Unknown  Unsupported URL Scores This graph can be viewed as a donut graph (default) or table and displays the total number of flows for each of the following URL reputation score categories: Trustworthy Low Risk Moderate Risk Suspicious High Risk Unknown Unsupported  File Health This graph can be viewed as a donut graph (default) or table and displays the total number of flows for each of the following file reputation categories: Good Files Bad Files Unknown Reputation Unsupported Blocked Sites Profile This bar graph displays the top ten licensed sites that had flows blocked during the selected time period.  Risky Sites Profile This bar graph displays the top ten licensed sites that had flows classified as risky during the selected time period.  Blocked Nodes Profile This bar graph displays the top ten private access nodes that had flows blocked during the selected time period.  Risky Nodes Profile This bar graph displays the top ten private access nodes that had flows classified as risky during the selected time period.  Note: The two Site Profile graphs are only displayed when the Scope field is Global or All Sites. The two Node Profile graphs are only displayed when the Scope field is Global or All Nodes. Quicklink toolbar The Security > Monitor page includes a Quicklink toolbar that appears floating at the bottom of the page. It includes a Security Logs icon that links to the Security Logs page, which is described in  View security logs . Related topics Security configuration View security logs