Event management
describes dashboard widgets related to event management
Artifact count
Displays: Distribution of security artifacts (indicators) by type, showing which types are most prevalent.
Business Value: Helps understand the nature of threats and indicators being tracked.
Metrics displayed:
-
Artifact count by type (IP addresses, domains, file hashes, URLs, and so on)
Count = Total number of artifacts of each type -
Relative percentage, compared to the most common type
Percentage = (Type Count ÷ Highest Type Count) × 100
Example
IP Address: 50 artifacts (100%)
File Hash: 42 artifacts (84%)
Domain: 25 artifacts (50%)
URL: 18 artifacts (36%)
Time Period: Configurable date range
Filters Applied:
-
Date range
-
Container labels
-
Optional user filter
-
Tenant (multi-tenant environments)
Data sources
Displays: Ingestion trends showing how many security events are coming from each data source (label) over time.
Business Value: Monitors data source health, identifies unusual spikes or drops, and helps with capacity planning.
Metrics displayed:
-
Time-series graph with one line per data source
-
Event counts per time period for each source
For each data source and time period, the count is the number of events created with that label during the time period. The system automatically fills in 0 values for time periods with no data, ensuring a complete time series.
Example display
Syslog source:
- Jan 1: 45 events
- Jan 2: 67 events
- Jan 3: 89 events
HTTP source:
- Jan 1: 23 events
- Jan 2: 34 events
- Jan 3: 56 events
Time period: Select hourly, daily, or monthly
Displays: Real-time ingestion rate showing how many new security events are being created over time.
Business value: Monitors system load, identifies trends, and helps detect anomalies in event ingestion.
Metrics displayed:
-
Time-series graph showing new event creation rate
-
Count of events per time period
Filters applied:
-
Date range
-
Configured data source labels
-
Optional user filter
-
Tenant (for multi-tenant environments)
Events
Displays: Comprehensive event statistics broken down by four dimensions: severity, sensitivity, status, and data source.
Business Value: Provides a complete picture of your security event landscape across multiple categorizations.
Metrics displayed:
-
Total Events: Overall count
-
By Severity: Distribution across severity levels
-
By Sensitivity: Distribution across sensitivity classifications
-
By Status: Distribution across workflow statuses
-
By Label: Distribution across data sources
For each dimension, events are counted and grouped. The count per category is the number of events matching that category criteria. All dimensions are calculated from the same event set, so totals match across views.
Example display:
Total: 1,234 events
By Severity:
- Low: 100 events
- Medium: 400 events
- High: 500 events
- Critical: 234 events
By Status:
- New: 300 events
- Open: 400 events
- Resolved: 534 events
Time Period: Configurable date range
Filters Applied:
-
Date range
-
Data source labels (permission-based)
-
Optional user filter
-
Container type filter
-
Tenant (for multi-tenant environments)
Events by status
Displays: A three-way breakdown of security events showing the distribution of severity levels across resolved, unresolved, and all events.
Business Value: Provides insight into event severity patterns and helps prioritize response efforts based on risk levels.
Metrics displayed: Three separate views, each counted and grouped by severity (Low, Medium, High, Critical, and so on)
-
Resolved: Events that have been closed; Status type =
Resolved -
Unresolved: Events still open or in progress; Status type =
NeworOpen -
All: Complete view of all events; Sum of
ResolvedandUnresolvedcategories
Example display
Resolved (250 total):
- Low: 50 events
- Medium: 100 events
- High: 75 events
- Critical: 25 events
Unresolved (150 total):
- Low: 20 events
- Medium: 60 events
- High: 50 events
- Critical: 20 events
Time Period: Configurable date range
Filters Applied:
-
Date range
-
Data source labels
-
Optional user filter
-
Enabled severity levels only
Incoming data sources
Displays: Real-time ingestion rate showing how many new security events are being created over time.
Business Value: Monitors system load, identifies trends, and helps detect anomalies in event ingestion.
Metrics displayed:
-
Time-series graph showing new event creation rate
-
Count of events per time period
The count per period is the number of events created during that specific time window. The system tracks event creation timestamps and aggregates them by the selected time period (hour, day, or month).
Example, daily view
Jan 1: 45 new events created
Jan 2: 67 new events created
Jan 3: 89 new events created
Jan 4: 52 new events created
A sudden spike might indicate a security incident or data source issue, while a drop might indicate connectivity problems.
Time Period: Selectable (hourly, daily, or monthly)
Filters Applied:
-
Date range
-
System default data source labels
-
Optional user filter
-
Tenant (multi-tenant environments)
Open
Displays: Your personal priority list - the top 100 unresolved security events assigned to you, sorted by SLA urgency.
Business Value: Helps you focus on the most time-sensitive events to prevent SLA breaches and ensure timely response.
Metrics Displayed:
-
Event ID and name
-
Current status
-
SLA Percentage: How much of the SLA window has elapsed
SLA % = (Time Elapsed ÷ Total SLA Window) × 100The widget prioritizes events closest to breaching their SLA (highest percentage shown first). Events with higher SLA percentages appear at the top, indicating they need immediate attention.
Example:
-
Event created: 2:00 PM
-
SLA window: 4 hours (due at 6:00 PM)
-
Current time: 5:30 PM
-
Time elapsed: 3.5 hours
-
SLA % = (3.5 ÷ 4) × 100 = 87.5%
Time Period: Last 30 days only
Filters Applied:
-
Events owned by current user
-
Non-resolved status only
-
Data source labels
-
Limited to 100 events
-
Performance
Displays: Four key performance indicators (KPIs) that measure how quickly your team responds to and resolves security events.
Business Value: Tracks operational efficiency and identifies opportunities for process improvement.
Metrics Displayed:
-
Mean Time To Resolution (MTTR): Average time from event creation to event closure
Example: "2 days 5 hours 30 minutes" On average, events are resolved in about 2.2 days
-
Max Time To Resolution (Max TTR): Longest time any single event took to resolve
Example: "15 days 3 hours 45 minutes" The slowest resolution took over 15 days
-
Mean Time To Triage (MTRT): Average time from event creation to first analyst assignment
Example: "4 hours 22 minutes" - Events are picked up within about 4 hours
-
Mean Dwell Time (Dwell Time) = Average time from event ingestion to resolution
Example: "1 day 2 hours 15 minutes" Total lifecycle averages about 1 day
Lower values generally indicate better performance, except where thorough investigation is required.
Time Period: Configurable date range
Filters Applied:
-
Date range
-
Optional user filter
-
Data source labels
-
Tenant (for multi-tenant environments)
Resolved
Displays: Event closure trends over time, separated into two categories: manually resolved and automatically resolved by playbooks.
Business Value: Demonstrates automation effectiveness and tracks resolution velocity.
Metrics Displayed:
-
Manual Closures: Events closed by analysts
-
Automated Closures: Events closed by automation (playbooks)
-
Total Resolved: Combined count
How Values Are Calculated:
For each time period, events are counted based on their close timestamp and closure method:
-
Manual Closure: An event is manually closed if a user triggered the closure (closing_owner_id field is populated)
-
Automated Closure: An event is automatically closed if a playbook triggered the closure (closing_owner_id field is empty/null)
Example, daily view:
Jan 1:
- Manual: 20 events
- Automated: 45 events
- Total: 65 events
Jan 2:
- Manual: 15 events
- Automated: 38 events
- Total: 53 events
A higher ratio of automated closures indicates effective automation.
Time Period: Selectable (hourly, daily, or monthly)
Filters Applied:
-
Date range
-
Container labels
-
Optional user filter
-
Tenant (multi-tenant environments)
Workload
Displays: Team capacity visualization showing how unresolved events are distributed across all security analysts.
Business Value: Identifies workload imbalances, helps with resource allocation, and highlights team members who may need support.
Metrics Displayed:
-
Total Unresolved: Combined count across all users
-
User Breakdown: Each user's count and relative percentage
User % = (User's Event Count ÷ Highest User's Count) × 100This calculation normalizes the view so the busiest person is shown as100%, so you can see relative workload.
Example:
-
John has 120 unresolved events (most on team)
-
Jane has 80 unresolved events
-
Mike has 40 unresolved events
Display:
-
John: 120 events (100%)
-
Jane: 80 events (66.7%)
-
Mike: 40 events (33.3%)
Time Period: All time (no date filtering)
Filters Applied:
-
Data source labels
-
Tenant (for multi-tenant environments)
-