---
title: "AI>Observe for Customer users"
canonical: "https://docs.aryaka.com/space/KNOW/841744401/AI%3EObserve%20for%20Customer%20users"
format: markdown
---
This topic describes the pages that can be accessed by AI>Observe users assigned the Customer role. For Customer users, AI>Observe includes the following pages: Incident Dashboard —View a summary of AI>Observe statistics and graphs for your incidents. Incident Insights —View trends, heatmaps, and generate reports on network incidents. Incidents —View statistics and a table of your network incidents. NBAD —View a series of statistics on the network anomalies data for your organization. MITRE ATT&CK Mapping —Gain insights on areas where there are gaps in your organization’s security defenses. Settings —Edit your AI>Observe user settings (for example, language and timezone). The Incident Dashboard is the Home page for Customer users. All other pages are accessed from the left navigation pane that appears when you select the Options icon. Depending on the type of data displayed, AI>Observe pages can included the following elements: Client drop-down list—Displays the name of your organization. Calendar—Allows you to select a predefined time period, or define a custom period to view data for. The dashboard displays data for the last four days by default and a maximum of 30 days. Create Channel—Displays the Create Channel pane where you can create a new channel. By default, the dashboard displays the Default channel, which displays all severities and device categories. You can create a custom channel, that, for example, only displays incident data that has High and Critical severities. Filter—Displays a dialog where you can filter the data displayed in the current channel. Filter options depend on the page being displayed but can include incident severity and status, device category, and the type of attack. The following elements can be used to interact with the tables displayed on the AI>Observe pages: Show or hide columns—Customize the columns that appear in the table. By default, all columns appear in the table. Clear one or more checkboxes in the Add or Remove Columns dialog to hide the corresponding column. Export—Exports the table data in a CSV file. The file is download to your default download directory. The file uses the following naming convention: Devices_ <companyName> _YYYY-MM-DD-HH_MM_SS, for example, Devices_ARYAKA_2025-02-05-15_53_18. Search columns—Search the contents of the selected column for a record that matches the string you enter. Partial matches are supported. Clear the text field to display unfiltered records. Details—Displays the Details page for the corresponding table row. Incident Dashboard The Incident Dashboard is the Home page for Customer users of AI>Observe. The following graphic displays an example of the Health Dashboard: The Incident Dashboard displays the following data, described in more detail in the associated sections: Incident Category Count tile Incident Severity Count tile Incidents Trend graph Incident Status graph Incident Categories with regard to Severity graph Incident Destination Address graph Top Incidents graph Incident Tactics graph Incident Techniques graph Incident Targeted Users graph Incident Source Address graph Incidents table Incident Category Count tile This tile displays the total number of incidents for four attack categories (UEBA, Web, Malware, and Network). Incident Severity Count tile This tile displays the total number of incidents for each severity (Low, Medium, and High). Incidents Trend graph This time series graph displays the total number of incidents for each day of the selected time period. The colors indicate the status of each incident. Incident Status graph This graph displays the distribution of incidents by their color-coded status. The following states are supported: For Approval—Incident raised by the Monitoring Team that is awaiting the analyst’s validation. Pending with Client—The CSIR team has not taken action on the incident. Need Further Input—Additional information is needed from the SOC Analyst in support of the recommended remediation. On Hold—The CSIR team has put the incident on hold pending clarification on action or recommendation from the analyst. Resolved—The incident is closed and the input requested has been furnished by the analyst. Closed—Remediation is complete and the incident has been closed. Open—Incident is acknowledged, and is being analyzed or otherwise responded to. False Positive—A mislabeled incident, one that resembles a known attack signature, but, in reality, is not a threat. Incident Categories with regard to Severity graph This graph displays the color-coded incident count by severity—Informational, High, Medium, and Low—for each corresponding incident category—Web, Network, Malware, UEBA, Threat Intel, Intrusion, and Malware Intel. Incident Destination Address graph This graph displays the IP addresses of up to 10 traffic destinations that have triggered the most incidents. Top Incidents graph This graph displays the name and count of up to 10 discovered incidents. Incident Tactics graph This graph displays the color-coded proportions of techniques mapped to the MITRE ATT&CK Framework found employed by the various incident types detected. Incident Techniques graph This graph displays the color-coded proportions of techniques employed that resulted in incidents. Incident Targeted Users graph This graph display the names of the top 10 users in your organization who have been targeted most frequently. Incident Source Address graph This graph displays the IP addresses of up to 10 traffic sources that have initiated the most incidents. Incidents table This table displays the following details for each incident that occurred in your network during the selected time period: Modified On—Timestamp for when the incident was modified. Created on—Timestamp for when the incident was created. Client—Name of the client being monitored. Incident Name—Name of the incident. Category—Category of attack that the incident belongs to (Web Network, Malware, UEBA, Threat Intel, Intrusion, or Malware Intel). Status—Current investigation status of the incident (Open, Closed, Resolved, Pending with Client, On Hold, In Progress, False Positive, Needs Further Input, or For Approval). Severity—Severity of the incident (High, Medium, Low, Real-time, or Informational). Incident ID—Identification number of the incident. Alert ID—Identification number of the alert.  Evidence Count—Total number of pieces of evidence that support the incident analysis. Actions—Click to view investigation details for the incident. Incident Insights Click Dashboards > Incident Insights in the left navigation pane to display the Incident Insights page. By default, the page displays the  Incidents Table  tab. It also includes the following tabs: Incidents Trend Incidents Heatmap Design These tabs are described in the sections that follow. Incidents Table tab Incidents Table tab contains a customizable 20-column table with a row for each incident. The default view of the table is shown in the following graphic: Click any table entry to display a summary dialog of that incident's detail. Click the Edit icon in the Actions column to view additional details about the selected incident. Incidents Trend tab The Incidents Trend tab displays a configurable incidents graph and the Incidents table. By default, the graph displays a line chart with the incident count plotted for each day using different color for each severity: The graph uses the selected date range (above the graph) and includes the following fields where you can edit the graph's display parameters: Chart Type—In addition to the default Line Chart, the following display options are available from this drop-down list: Stacked Column Chart Stacked Bar Chart Grouped Column Chart Grouped Bar Chart Trend Type—In addition to the default Daily, the following display options are available from this drop-down list: Weekly Monthly Day of Week Group By—In addition to the default Severity, the Category display option is available from this drop-down list. Below the graph is the  Incidents table . Incidents Heatmap tab The Incidents Heatmap tab displays a configurable incidents heatmap grid and the Incidents table. By default, the grid displays the incident count for each month for the selected time period for each severity: Note the following in the graphic: The intensity of the red is designed to give you an at-a-glace summary of the incident count. Only complete months appear in the grid. For example, this grid was displayed for the 11/01/24 - 02/20/25 time period, but the grid only displays Nov 2024, Dec 2024, and Jan 2025. By default, no subgroup is displayed. Totals are calculated for each month and each severity. The grid uses the selected date range (above the grid) and includes the following fields where you can edit the graph's display parameters: Stack By—In addition to the default Monthly, the following display options are available from this drop-down list: Daily Weekly Day of Week Group By—In addition to the default Severity, the following display options are available from this drop-down list: Category Incident Subgroup By—In addition to the default None, the following display options are available from this drop-down list: Severity Category Incident The following heatmap grid shows the incident count for the same time period (11/01/24 - 02/20/25) and defaults (Monthly and Severity) but with the Subgroup field set to Incident, which displays the Incident column and an incident type for each severity: Below the grid is the  Incidents table . Design tab The Design tab allows you to design custom on-screen reports and to visualize your incident data using configurable design elements and predefined filters. By default, the report displays a stacked column chart showing the daily incident count by color-coded severity: The report uses the selected date range (top of page) and includes the following fields where you can edit the report's display parameters: Display option—Click the Stacked Column Chart drop-down list (the field displays the current selection, in this case the default option) and select your desired display option. Count option—Click the Count drop-down list (the field displays the current selection, in this case the default option) and select how you want the data in the graph to be displayed. Severity option—By default, all severities are displayed. Click Severity to select the severities you want to include in the graph. Created DOW (day of week) option—By default, all days are displayed. Click Created DOW to select the days of the week that you want to include in the graph. Incidents The Incidents page displays the results of the AI-based analysis of your Aryaka log files, which indicates detected high-concern security events that are undergoing mitigation and remediation. The Incidents page is shown in the following graphic: The Incidents page displays the following data, described in more detail in the associated sections: Severity Wise Summary tile Attack Type Wise Summary tile Status Wise Summary tile Incidents table Severity Wise Summary tile This tile displays the number of incidents with each severity level (Critical, High, Medium, Low, and Info) for the selected time period.  Attack Type Wise Summary tile This tile displays the number of incidents for each type of attack (UEBA, Network, Malware, and Web Attack) for the selected time period.  Status Wise Summary tile This tile displays the number of incidents with each status (Open, On-Hold, Final Review, Resolved, For Approval, Closed, Pending-with-Client, and Need-Further-Input) for the selected time period.  Incidents table This table displays the following details for each incident that occurred in your network during the selected time period: Modified On—Timestamp for when the incident was modified. Created on—Timestamp for when the incident was created. Incident Name—Name of the incident. Category—Category of attack that the incident belongs to (Web Network, Malware, UEBA, Threat Intel, Intrusion, or Malware Intel). Status—Current investigation status of the incident (Open, Closed, Resolved, Pending with Client, On Hold, In Progress, False Positive, Needs Further Input, or For Approval). Severity—Severity of the incident (Critical, High, Medium, Low, or Informational). SLA Indicator—Displays the risk of violating the service level agreement using Critical, High, Medium, Low, or Informational. Incident Type—Method by which the incident was raised (Manual or Auto). Incident ID—Identification number of the incident. Alert ID—Identification number of the alert. Evidence Count—Number of pieces of supporting evidence for the incident. Actionable—Displays a recommendation on how to address the incident. Incident Analysis—Details the procedural logic used to investigate the activity that caused the incident. Investigation Steps—Steps taken to investigate the incident. Containment Steps—Steps taken to contain the incident. Description—Description of the incident. Device Category—Type of device involved in the incident. Action Name—Response to the incident. Source Address—IP address that initiated the incident. Source Port—Port number used at the IP address that initiated the incident. Destination Address—IP address that the traffic associated with the incident was sent to. Destination Port—Port number at the IP address that the traffic associated with the incident was sent to. Source User Name—User name associated with the incident’s source IP address or device. Device Address—IP address of the device associated with the incident. Ticket ID—Unique identifier of a support ticket associated with the incident. Actions—Click the icon to view the Details page for the associated incident. NBAD Click Anomaly Detection > NBAD in the left navigation pane to display the NBAD page. The NBAD page displays a series of statistics on the network anomalies data for your organization. Network Behavior Anomaly Detection (NBAD) provides your organization with broad insights on network usage by monitoring your network for unusual activity or trends. By examining your organization’s logs, AI>Observe can determine baseline activity for your organization’s users and entities, allowing the identification of anomalous activity when it occurs.  The NBAD page displays the following data, described in more detail in the associated sections: Top Anomalies graph Anomalies Trend graph Anomalies Data table Top Anomalies graph This graph displays the distribution of the following anomaly categories for the selected time period: Possible Scanning Attack—A high number of unique source addresses were detected. This can indicate a scanning attack or that a vulnerability is being exploited. Host Scanning—A high number of unique destination addresses were detected. This can indicate a scanning attack or that a vulnerability is being exploited. Port Scanning—A high number of destination ports were detected. This can indicate port scanning.  Traffic Increase—A high amount of network traffic was detected. Allowed Traffic Increase—A high number of connections were accepted. This can indicate that a vulnerability is being exploited. Possible DOS Attack—A high number of connections were denied. This can indicate a scanning attack.  Anomalies Trend graph This time series graph plots the number of each type of color-coded anomaly (Possible Scanning Attack, Host Scanning, Port Scanning, Traffic Increase, Allowed Traffic Increase, or Possible DOS Attack) that occurred over the selected time period.  Anomalies Data table This table displays the following details for the devices where anomalies were detected by AI>Observe during the selected time period: End Date—Timestamp of the end of the unusual network behavior. Total Events—The total number of events that occurred during the anomaly.  Device Vendor—Name of the device manufacturer. Device Product—Network device where the anomaly was observed. Severity—Severity level of the anomaly. Risk Score—Number that quantifies the level of risk that the anomaly poses for your organization. The score is determined based on the device criticality and the incident severity. A higher risk score indicates a higher risk to your organization.  MITRE ATT&CK Mapping Click MITRE ATT&CK Mapping in the left navigation pane to display the MITRE page. This page uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework to provide insight on areas where there are gaps in your organization’s security defenses.  To generate data on the MITRE page, click the Select Date Range drop-down and select a date range (up to seven days) to view data for. Click Compute to refresh the page with the requested data.  By default, the page displays the  Correlation Dashboard tab . It also includes the  Threat Hunting Cases tab . These tabs are described in the sections that follow. Correlation Dashboard tab  The Correlation Dashboard tab maps your organization’s security controls to the tactics and techniques outlined in the MITRE ATT&CK framework to assist you in identifying security gaps and prioritizing their mitigation. The tab displays data for alerts by default. Click the toggle to display data for your organization’s incidents. The following graphic shows the Correlation Dashboard tab for alerts: The ATT&CK Matrix displays color-coded tiles that contain a count for each of the 14 alert categories. Below the matrix, the categories are grouped into the following four summary panes and display the counts for the included subcategories: Pre-Attack Reconnaissance Resource Development Initial Attack Initial Access Execution Persistence Privilege Escalation Defense Evasion Discover Data Credential Access Discovery Lateral Movement Collection Command and Control Extract Data Exfiltration Impact Below the summary panes, the page displays the following graphs: Top Triggered Techniques Top Malicious Events High Traffic Assets High Risk Assets Threat Hunting Cases tab The Threat Hunting Cases tab displays correlations between your organization’s detected alerts or between your organization’s detected incidents The tab displays data for alerts by default. Click the toggle to display data for your organization’s incidents. Depending on your toggle selection, this tab displays the Alerts table or the Incidents table. These tables include the following columns: Created On Attack Scenario Context Factor Kill Chain Steps Tactics Techniques Click the Expand   icon in a table row to view it’s correlated alerts or incidents. Settings The Settings pages allows you to configure your user settings for AI>Observe. The Settings page includes the following sections: Language—Select a language for your users. Timezone—Select a timezone for your users. MFA QR Code—QR code that contains a one-time password for login. Note that login occurs through MyAryaka—this QR code is not accessible to users.  Settings & Privacy—Reset your password. Note that there is never a need to change your password from this location. The shared SSO functionality in MyAryaka passes your actual credentials to AI>Observe. Channel—Add or edit channels. By default, the AI>Observe pages display the Default channel, which displays all severities and device categories. You can create a custom channel, that, for example, only displays incident data that has High and Critical severities. In this topic Related topics AI>Observe AI>Observe for Customer Admin users Security dashboard