---
title: "Monitor SaaS Apps Access Control security engine"
canonical: "https://docs.aryaka.com/space/KNOW/529039480/Monitor%20SaaS%20Apps%20Access%20Control%20security%20engine"
format: markdown
---
The Engine: SaaS Apps Access Control page allows you to monitor the amount of traffic that was permitted or denied by your SaaS Apps Access Control rules and the action that was taken based on your rule configuration for the selected scope and time period. If it is not already open, complete the following procedure to view the Engine: SaaS Apps Access Control page: To view the Engine: SaaS Apps Access Control page Log in to MyAryaka. The Home page appears. Click  Security  >  Monitor  in the left navigation pane. The Security: < siteName > page appears and displays a series of tables and graphs.  Click the  Scope  field and select the site or node for which you want to monitor the SaaS Apps Access Control security engine. Click the  Time  field and select the time period for which you want to monitor the SaaS Apps Access Control security engine. Click the  SaaS Apps Access Control  security engine in the Engine Sequencing diagram. The Engine: SaaS Apps Access Control page appears and displays an Engine Sequencing diagram and a series of graphs, which are described in detail later in this topic. Engine Sequencing diagram The Engine Sequencing diagram displays the security engine that the SaaS Apps Access Control engine receives traffic from and the engines that it sends traffic to after inspection. Click the source engine to view the  Monitor Next Generation Firewall security engine  page. Click the destination engine to view the  Monitor URL Reputation security engine  page.  The following graphic shows an example of the SaaS Apps Access Control engine: The red value displayed on the SaaS Apps Access Control engine indicates the number of requests that were dropped or denied by the engine over the selected time period. Hover over the blue circle to the left of the SaaS Apps Access Control engine to view the number of inbound requests for the selected time period. Hover over the blue circle to the right of the SaaS Apps Access Control engine to view the number of outbound requests for the selected time period. Included graphs The sections that follow describe each of the graphs included on the Engine: SaaS Apps Access Control page. Requests This time series graph displays the total number of HTTP requests, the number of permitted requests, and the number of denied requests for the selected scope over the selected time period. Actions This graph can be displayed as a donut graph (default) or as a table. It displays the total number of requests where the following actions were taken: Permit—Traffic is permitted and sent to the next security engine for inspection. Forbidden—Traffic is denied and the client receives a  403 Forbidden  error. Block—Traffic is denied and the user is presented with the  Blocking page .  Log Only—Traffic is permitted and sent to the next security engine for inspection. This is intended as a temporary action while you evaluate traffic. After you have evaluated traffic, update the rule with one of the other actions. Rule actions are configured in your  SaaS Apps Access Control rules . Blocked Sites This bar graph displays the top ten licensed sites that had requests blocked during the selected time period.  Blocked Nodes This bar graph displays the top ten private access nodes that had requests blocked during the selected time period.  The Blocked Sites graph is only displayed when the Scope field is Global or All Sites. The Blocked Nodes graph is only displayed when the Scope field is Global or All Nodes. In this topic Related topics Configure a SaaS Apps Access Control ruleset Monitor security