8.2 Monitoring with the Security App Dashboards
Key Takeaways
The Security Dashboards page lists Elastic's default dashboards and any custom dashboard tagged Security Solution.
The Overview dashboard shows a live feed, alert and event histograms, host and network events by data source, and ingested threat indicators per source.
The Detection & Response dashboard shows alerts by status and severity, cases by status, the top four rules with open alerts, and up to 100 hosts and users by alert severity.
The Data Quality dashboard checks indices for ECS mapping problems (red treemap nodes mean incompatible fields) but excludes cold, frozen and remote-cluster data.
The Detection rule monitoring dashboard reads the Kibana event log to show rule execution status, durations and schedule delays across all spaces.
Elastic's objective monitor security-related events with dashboards in the Security App refers to the dashboards built into Elastic Security. They are different from the Kibana dashboards you build yourself (Chapter 7), although the two meet on the Security Dashboards page.
The Security Dashboards Page
Select Dashboards in the Security app to see the default dashboards and any custom dashboards. From this page you can also:
- Click Create Dashboard to build a new custom dashboard.
- Search custom dashboards by name or description and filter them by tag.
- Make a custom dashboard appear here by giving it the tag Security Solution.
Across these dashboards, hovering over a chart or table shows Inspect (see the Elasticsearch query), Add to new or existing case, and often Open in Lens. Numbers and names are links into the Alerts page, Cases, Timeline, or host and user details.
Overview Dashboard
A high-level snapshot of alerts and events that helps you judge overall health and spot anomalies:
- Live feed: recently created cases, favorited Timelines and Elastic Security news.
- Histograms: detections, alerts and events over the selected time range, with a Stack by menu. Click and drag to zoom into a period.
- Host and network events: event and host counts grouped by data source, such as Auditbeat or Elastic Defend. A sudden drop for one source is an early sign of an ingestion problem.
- Threat Intelligence: the number of ingested threat indicators, the enabled threat intelligence sources, and indicators per source, with View indicators for detail.
Detection & Response Dashboard
Built for day-to-day SOC operations:
- Alerts by status and severity, and Cases by status, for the selected time range.
- Open alerts by rule: the top four rules with open alerts, by severity and count.
- Recently created cases: the four newest cases.
- Hosts by alert severity and Users by alert severity: up to 100 each.
Click a number to open those alerts on the Alerts page, or hover and choose Investigate in timeline. Click a rule, case, host or user name to open its details.
Entity Analytics Dashboard
A central view of emerging risk from hosts, users and anomalies. It needs a Platinum subscription or higher, and the risk scoring engine must be on for risk data.
- Entity KPIs: the number of critical hosts, critical users and anomalies.
- Host Risk Scores and User Risk Scores: totals and the most recently recorded scores, with risk levels and alert counts. Filter by risk level, open the host or user flyout, add values to Timeline, or click View all to jump to the Hosts or Users page.
- Anomalies: machine learning anomaly results.
Data Quality Dashboard
Shows whether indices are correctly mapped to ECS. Correct mapping is what lets rules, Explore pages and dashboards use your data.
- Nothing appears until you check indices. Check all checks every index in the current data view, and expanding one index checks just that index.
- A treemap sizes indices by storage. Blue means not yet checked, green means checked with no incompatible fields, and red means one or more incompatible fields.
- Expanding a result shows which fields are incompatible or not ECS-compliant. You can create a case or a Markdown report from the results, and use Chat on incompatible fields to ask AI Assistant for help.
- Results are stored in
.kibana-data-quality-dashboard-results-<spaceId>. - It does not show data from cold or frozen tiers or from remote clusters.
- Checking an index needs
monitorormanage,view_index_metadataormanage_ilm, andreadon that index.
Kubernetes Dashboard
Shows Linux process data from Kubernetes clusters, collected by Elastic Defend for Cloud Workload Protection for Kubernetes on nodes with Linux kernel 5.10.16 or higher.
- Charts summarize the monitored infrastructure.
- A tree lets you navigate by Logical view (cluster, namespace, pod, container image) or Infrastructure view.
- The sessions table offers View details, Open in Timeline, Run Osquery, Analyze event and Open Session View.
Cloud Security Dashboards
The Cloud Security Posture dashboard summarizes posture findings from cloud and Kubernetes posture management (CSPM and KSPM) integrations. The Cloud Native Vulnerability Management dashboard summarizes vulnerability findings from CNVM. They populate only when those integrations are deployed.
Detection Rule Monitoring Dashboard
Monitors the health and performance of detection rules, using the Kibana event log:
- Rule KPIs: rules enabled, total executions and response statuses.
- Executions by rule type and by status over time.
- Total rule execution duration, rule schedule delay, search/query duration and indexing duration (writing alerts to
.alerts-security.alerts-*). - Top 10 rules: the slowest, most delayed, and those with the most Failed or Warning statuses.
It needs at least Read on the Dashboard and Security features, plus read on .kibana-event-log-*. It includes data from all spaces, so filter by space when needed.
Choosing the Right Dashboard
| Monitoring Question | Dashboard |
|---|---|
| Is overall alert and event volume normal? Are all data sources still reporting? | Overview |
| Which rules have the most open alerts, and which hosts and users are affected? | Detection & Response |
| Which hosts and users carry the most risk right now? | Entity Analytics |
| Is my data mapped to ECS so rules and pages work? | Data Quality |
| What are processes doing inside my Kubernetes clusters? | Kubernetes |
| How is my cloud posture and vulnerability exposure? | Cloud Security Posture / Cloud Native Vulnerability Management |
| Are my rules running on time, fast enough and without failures? | Detection rule monitoring |
The Alerts page itself is also a monitoring surface. Its Summary, Trend, Counts and Treemap views show alert volume and distribution by any field.
Several prebuilt rules stopped producing alerts after a new firewall integration was added, and an analyst suspects the new data is not mapped to ECS. Which Security app dashboard is designed to check this?
Detection & Response dashboard
Data Quality dashboard
Entity Analytics dashboard
Overview dashboard
A SOC lead built a custom Kibana dashboard for phishing triage and wants it listed on the Security app's Dashboards page next to the default dashboards. What must be done?
Save it in the default space only
Give it the tag Security Solution
Export it as NDJSON and import it through Fleet
Add it to a Timeline template
A detection engineer wants to see which rules are slowest, which start late relative to their schedule, and which have the most Failed statuses. Which dashboard provides this?
Detection rule monitoring dashboard
Detection & Response dashboard
Kubernetes dashboard
Cloud Security Posture dashboard
Which items appear on the Detection & Response dashboard? (Select all that apply.)
Select all that apply
Open alerts by rule (the top four rules)
Recently created cases
Hosts by alert severity
ECS mapping results per index
Sections you finish are checked off in the contents.