An incident in Microsoft 365 Defender is a collection of correlated alerts and associated data that make up the story of an attack. Microsoft 365 Read more
Visualizer
Web Data Source Field Definitions
Field Name Definition appsite Friendly name for a Website or Application authtype blocked This occurs because the user is not authorized to access the site, Read more
Palo Alto Data Source Field Definitions
Field Name Definition action Action taken for the session; values are alert, allow, deny, drop, drop-all-packets, reset-client, reset-server, reset-both, block-url. action_source Specifies whether the action Read more
Getting Started – Visualizer
After logging into the visualizer you will be presented with a default blank dashboard. To start adding reports panels to your new dashboard please follow Read more
Manage Dashboards
To manage your dashboard follow these steps:
Add a new Dashboard
To add a new dashboard following these steps:
Panel Filter
How to create a panel filter:
Print Panel
To print a panel, follow these instructions:
Delete Panel
To delete a panel follow these steps:
Add Panel
To add a new panel follow these steps: