View Security Incident Response Health dashboard
Security Incident Response Health dashboard feature provides a centralized view of critical aspects related to incident response process implementation, issues/errors encountered, and performance metrics. It serves as a vital tool for monitoring and optimizing the effectiveness of an organization's security incident response capabilities.
Before you begin
Role required: sn_si.admin, or sn_si.analyst, or sn_si.analytics_read - View dashboard.
About this task
You can monitor the health of the security incidents using the widgets and trend charts for each application. These statistics present a comprehensive health score detailing the configuration state and remediation
effectiveness within the SIR applications. The Security Incident Response Health dashboard supports the following four tabs:
- Process: The tab displays a summary of all the incidents from various alert sensors grouped on a weekly basis.
- Implementation: This tab displays the customizations that the customers perform in their instances covering script includes, business rules, flows, and upgrades.
- Issues/Errors: The tab displays widgets highlighting errors in integration processes, discrepancies during the ingestion of raw incident data, outbound HTTP errors in SIR applications, and any issues arising during the execution of playbooks.
- Performance: This tab displays the performance issues in the SIR applications, including slowness in performance queries, business rules, and scripts.