Security Center provides dashboards for network logs, host logs, and security logs on the Log Reports page.

After you enable the log analysis function, Security Center automatically creates a report dashboard page.

Log type Log report
Network logs DNS access center
Network session center
Web access center
Host logs Login center
Process center
Connection center
Security logs Baseline center
Vulnerability center
Alarm center
Log reports

Network logs

Network logs contain the following log reports:

  • DNS Access Center

    Provides a global overview of DNS queries on the server, which includes the success rate of external DNS queries, and the distribution and trends of both local and external DNS queries.

    Chart Type Default time range Description Example
    External DNS Traffic Single value comparison Today (Time Frame)/Compared with Yesterday The number of external DNS traffic packages in a period today and the change compared to the same period yesterday. 10.0, 0.01%
    External DNS Successful Query Ratio Single value comparison Today (Time Frame)/Compared with Yesterday The success rate of external DNS queries and the change compared to yesterday. 100%, 0.01%
    Unique DNS Queried Site Single value comparison Today (Time Frame)/Compared with Yesterday The number of domain names that a unique DNS queries and the change compared to yesterday. 10.0, 0.01%
    Local DNS Traffic Single value comparison Today (Time Frame)/Compared with Yesterday The number of local DNS traffic packages and the change compared to yesterday. 1000, 0.01%
    External Query Device Distribution Map (global) Today (Time Frame) The global geographical distribution of public network devices that initiate DNS queries. N/A
    External DNS Traffic Trend Column chart and line chart Today (Time Frame) The number of requests and the success rate trends of external DNS queries per hour. N/A
    Local DNS Traffic Trend Column chart Today (Time Frame) The trend of the number of requests for local DNS queries per hour. N/A
    External DNS Most Queried Site Top 20 Pie chart Today (Time Frame) The 20 domain names that initiate the most DNS queries. N/A
    Local DNS Device with Most Query Top 20 Pie chart Today (Time Frame) The 20 instances that initiate the most local DNS queries. N/A
    Local DNS Most Queried Site Top 20 Pie chart Today (Time Frame) The 20 domain names that initiate the most local DNS queries. N/A
  • Network Session Center

    Provides a global overview of asset-related network sessions, which includes connection trends, connection distributions, connection destinations, access trends, and access distributions.

    Chart Type Default time range Description Example
    Network Session Single value comparison Last 1 hour/Compared with Yesterday The number of network sessions in a period today and the change compared to the same period yesterday. 10.0, -0.01%
    Unique Destination IP Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique destination IP addresses in network sessions and the change compared to yesterday. 10.0, -0.01%
    Unique Source IP Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique source IP addresses in network sessions and the change compared to yesterday. 10.0, 0.01%
    Unique Destination Port Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique destination ports in network sessions and the change compared to yesterday. 10.0, -0.01%
    Network Connection Trend (Protocol) Flow diagram Today (Time Frame) The trend of the number of protocols, such as TCP and UDP, used by network sessions per hour. N/A
    Network Connection Trend (Asset Type) Double-line chart Today (Time Frame) The trend of the number of assets, such as ECS and SLB, used by network sessions per hour. N/A
    Session Protocol Distribution Pie chart Today (Time Frame) The distribution of connection protocols, such as TCP and UDP, used by network sessions. N/A
    Destination Port Top 10 Pie chart Today (Time Frame) The distribution of the 10 destination ports with the most network sessions. N/A
    Related Asset Type Distribution Pie chart This Month (Time Frame) The distribution of types of assets associated with a network session. The types include ECS and SLB. N/A
    Destination Distribution (World) Map (global) Today (Time Frame) The global geographical distribution of destination IP addresses of outbound sessions. N/A
    Source Distribution (World) Map (global) Today (Time Frame) The global geographical distribution of source IP addresses of inbound sessions. N/A
    Destination Distribution (China) Map (China) Today (Time Frame) The geographical distribution of destination IP addresses of outbound sessions in China. N/A
    Source Destination (China) Map (China) Today (Time Frame) The geographical distribution of source IP addresses of inbound sessions in China. N/A
  • Web Access Center

    Provides a global overview of external HTTP requests and accesses to the web services of a host. This view includes request success rate, access trends, success efficiency, distribution of accessed domain names, and other related distributions.

    Chart Type Default time range Description Example
    Valid Request Ratio Single value comparison Today (Time Frame)/Compared with Yesterday The success rate of HTTP requests and the change compared to yesterday. The success rate is calculated as the percentage of returned values that are less than 400. 0.01%, 10.00
    Web Access Count Single value comparison Today (Time Frame)/Compared with Yesterday The number of HTTP requests in a period today and the change compared to the same period yesterday. 1000, -0.01%
    Unique Destination Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique destination IP addresses of HTTP requests and the change compared to yesterday. 10.0, -0.01%
    Unique Source Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique source IP addresses of HTTP requests and the change compared to yesterday. 1000, 0.01%
    Web Access Trend and Valid Ratio Column chart and line chart Today (Time Frame) The number of HTTP requests per hour and the trend of the success rate. The success rate is calculated as the percentage of returned values that are less than 400. N/A
    Unique Source/Destination Trend Double-line chart Today (Time Frame) The number of unique source IP addresses and destination IP addresses per hour. N/A
    Access Status Distribution Flow chart Today (Time Frame) The distribution of returned status code, such as 2xx and 3xx, per hour. N/A
    Accessed Site Top 10 Histogram Today (Time Frame) The distribution of the 10 domain names that are accessed the most. N/A
    Content Type Distribution Top 10 Pie chart Today (Time Frame) The 10 content types that are requested the most, such as text/plain. N/A
    Referer Table Today (Time Frame) The 20 referers that are referred the most. The table contains URL, Host, and Total Count. N/A

Host logs

Host logs contain the following log reports:

  • Login Center

    Presents a logon overview for hosts, which includes their geographical distribution, trends, logon ports, and logon types of source and destination IP addresses.

    Chart Type Default time range Description Example
    Login Count Single value comparison Last 1 hour/Compare with Yesterday The number of logons in a period today and the change compared to the same period yesterday. 10.0, 10%
    Logged In Device Count Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique hosts that are logged on to and the change compared to yesterday. 10, -10%
    Unique Login Source IP Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique source IP addresses that are used to log on to hosts and the change compared to yesterday. 10, 10%
    Unique Login User Name Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique usernames that are used to log on to hosts and the change compared to yesterday. 10, 10%
    Login on Device Trend Column chart and line chart Today (Time Frame) The trend of the number of hosts that are logged on to and the number of logons per hour. N/A
    Login Method Trend Flow diagram Today (Time Frame) The trend of the number of logons that use different methods, such as RDP and SSH, per hour. N/A
    Login Method Distribution Pie chart 4 Hours (Relative) The distribution of different logon methods, such as RDP and SSH. N/A
    Device Distribution Map (global) 4 Hours (Relative) The global geographical distribution of logged on hosts with public IP addresses. N/A
    Login Source Distribution Map (global) 4 Hours (Relative) The global geographical distribution of the source IP addresses used to log on to hosts with public IP addresses. N/A
    Unique Source IP Distribution Map (global) 4 Hours (Relative) The global geographical distribution of the unique logon source IP addresses used to log on to hosts with public IP addresses. N/A
    User with Most Login Top 10 Pie chart 4 Hours (Relative) The 10 usernames that are used most frequently. N/A
    Port with Most Login Top 10 Pie chart 4 Hours (Relative) The 10 destination ports that are used most frequently. N/A
    Activated User List Table 4 Hours (Relative) The first 30 accounts available on the host. N/A
    Source IP and User with Most Login Top 30 Table 4 Hours (Relative) The 30 usernames that are used to log on to the host most frequently and the logon source information. The table contains Source Network, Source IP, Login User, Login Method, Login Destination Count, and Login Count. N/A
  • Process Center

    Presents a process overview for hosts, which includes process initiation trends, process distribution, process types, and the distribution of specific Bash and Java program initiations.

    Chart Type Default time range Description Example
    Process Start Count Single value comparison Last 1 hour/Compared with Yesterday The number of process initiations in a period today and the change compared to the same period yesterday. 10000, 0.01%
    Related Device Count Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique hosts that initiate processes and the change compared to yesterday. 10.0, 0.01%
    Unique Process Name Count Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique processes initiated and the change compared to yesterday. 10.0, 0.01%
    Device Count Column chart and line chart Today (Time Frame) The trend of the number of hosts that initiate processes and the number of unique processes per hour. N/A
    Process Start Trend Line chart Today (Time Frame) The average number of processes initiated on each host per hour. N/A
    Device Distribution Map (global) Today (Time Frame) The global geographical distribution of hosts that initiate processes (for hosts with public IP addresses). N/A
    Process Start Count Distribution on Device Map (global) Today (Time Frame) The global geographical distribution of the process events on hosts with public IP addresses. N/A
    Most Started Process Top 20 Table Today (Time Frame) The 20 processes that are most frequently initiated. The table contains Process Name, Process Path, and Start Count. N/A
    Process that Started Most Bash Top 20 Table Today (Time Frame) The 20 processes that initiate Bash the most. The table contains Parent Process and Start Count. N/A
    Java File with Most Start Count Top 30 Table Today (Time Frame) The 30 Java files that initiate the most processes. The table contains the Jar File Name, Jar File Path, and Start Count. N/A
    Device with Most Process Started Top 30 Table Today (Time Frame) The 30 clients that initiate the most processes. The table includes Device, Total Started Process Count, Most Started Command Line, Related Process, Start Count, and Ratio. N/A
  • Connection Center

    Presents an overview of the connection changes for hosts, which includes the connection distribution, connection trends, destinations, and accesses.

    Chart Type Default time range Description Example
    Connection Event Single value comparison Last 1 hour/Compare with Yesterday The number of connection changes in a period today and the change compared to the same period yesterday. 10.0, -0.01%
    Related Device Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique hosts that have connection changes and the change compared to yesterday. 10.0, 0.01%
    Unique Process Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique processes that have connection changes and the change compared to yesterday. 10.0, 0.01%
    Unique Source IP Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique source IP addresses that have connection changes and the change compared to yesterday. 10.0, 0.01%
    Unique Destination IP Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique destination IP addresses that have connection changes and the change compared to yesterday. 1000, 0.01%
    Network Connection Trend Double-line chart 1 Hour (Relative) The trend of the number of hosts on which network connection events occur and the number of events per hour. N/A
    Connection Type Trend Double-line chart 1 Hour (Relative) The distribution trend of connection types, such as in and out connections, involved in connection changes per hour. N/A
    Connection Type Distribution Pie chart 1 Hour (Relative) The distribution of connection types, such as in and out connections, involved in connection changes. N/A
    Protocol Distribution Pie chart 1 Hour (Relative) The distribution of connection protocols, such as TCP and UDP, involved in connection changes. N/A
    Device Distribution Map (global) 1 Hour (Relative) The global geographical distribution of hosts that have connection changes. N/A
    Device Event Distribution Map (global) 1 Hour (Relative) The global geographical distribution of connection changes on hosts with public IP addresses. N/A
    Connection Out Destination Distribution Map (global) 1 Hour (Relative) The global geographical distribution of the destination IP addresses of outbound connection changes. N/A
    Connection In Source Distribution Map (global) 1 Hour (Relative) The global geographical distribution of the source IP addresses of inbound connection changes. N/A
    Device with Most Connection Out Top 30 Table 1 Hour (Relative) The 30 devices that have the most outbound connection changes. The table contains Device, Connection Out Count, Connection Destination Count, Destination Port Sample. N/A
    Device with Most Connection In Top 30 Table 1 Hour (Relative) The 30 devices that have the most inbound connection changes. The table contains Device, Listen IP, Connection In Count, Listen Port Count, and Port Sample. N/A
    Device with Most Connection Out Target Top 30 Table 1 Hour (Relative) The 30 devices that have the most destinations of outbound connection changes. The table contains Device, Connection Out Count, and Destination Port Sample. N/A
    Ports with Most Connection In Top 30 Table 1 Hour (Relative) The 30 listening ports that have the most inbound connection changes. The table contains Listen Port, Connection In Count, and Process Sample. N/A
    Process with Most Connection Out Top 30 Table 1 Hour (Relative) The 30 processes that have the most outbound connection changes. The table contains Process Name, Connection Event Count, Related Device Count, and Path Sample. N/A
    Process with Most Connection In Top 30 Table 1 Hour (Relative) The 30 processes that have the most inbound connection changes. The table contains Process Name, Connection Event Count, Related Device Count, and Path Sample. N/A

Security logs

Security logs contain the following log reports:

  • Baseline Center

    Provides a global overview of baselines, which includes the distribution of issues, the trend of newly occurred issues, the trend of handled issues, and issue states.

    Chart Type Default time range Description Example
    Related Device Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique hosts that have baseline issues and the change compared to yesterday. 10.0, 0.01%
    New Baseline Single value comparison Today (Time Frame)/Compared with Yesterday The number of new baseline issues and the change compared to yesterday. 10.0, -0.01%
    Verify Baseline Single value comparison Today (Time Frame)/Compared with Yesterday The number of verified baseline issues and the change compared to yesterday. 10.0, -0.01%
    High Level Baseline Single value comparison Today (Time Frame)/Compared with Yesterday The number of high-priority baseline issues and the change compared to yesterday. 10.0, 0.01%
    Baseline Operation Trend Flow chart Today (Time Frame) The trend of the number of operations on baseline issues, such as addition and verification per hour. N/A
    Baseline Subtype Trend Flow chart Today (Time Frame) The trend of the number of baseline subtypes, such as system account security and registration, per hour. N/A
    Baseline Status Trend Flow chart Today (Time Frame) The trend of the number of baseline issues in each state, such as unfixed and fixed, per hour. N/A
    Baseline Operation Distribution Doughnut chart Today (Time Frame) The distribution of operations on baseline issues, such as addition and verification. N/A
    Baseline Subtype Distribution Doughnut chart Today (Time Frame) The distribution of baseline subtypes, such as system account security and registration. N/A
    Baseline Status Distribution Doughnut chart Today (Time Frame) The latest states of baselines, such as unfixed, fixed, and fix failed.
    Notice If a baseline issue has multiple states, the latest state is used.
    N/A
    New Baseline Top10 Doughnut chart Today (Time Frame) The 10 baselines with the most new issues. N/A
    Verify Baseline Top10 Doughnut chart Today (Time Frame) The 10 baselines with the most verified issues. N/A
    Baseline Client Distribution Top20 Table Today (Time Frame) The 20 hosts that have the most baseline issues. The table contains Client, Baseline Event, New, Verify, High Level, and Medium Level. N/A
  • Vulnerability Center

    Provides a global overview of vulnerabilities, which includes vulnerability distribution, trend of new, verified, and fixed vulnerabilities, and states of vulnerabilities.

    Chart Type Default time range Description Example
    Related Device Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique hosts that have vulnerabilities and the change compared to yesterday. 10.0, 0.01%
    New Vulnerability Single value comparison Today (Time Frame)/Compared with Yesterday The number of new vulnerabilities and the change compared to yesterday. 10.0, 0.01%
    Verify Vulnerability Single value comparison Today (Time Frame)/Compared with Yesterday The number of verified vulnerabilities and the change compared to yesterday. 10.0, -0.01%
    Fix Vulnerability Single value comparison Today (Time Frame)/Compared with Yesterday The number of fixed vulnerabilities and the change compared to yesterday. 10.0, -0.01%
    Vulnerability Operation Trend Flow chart Today (Time Frame) The trend of the number of operations on vulnerabilities, such as addition and verification, per hour. N/A
    Vulnerability Type Trend Flow chart Today (Time Frame) The trend of the vulnerability types per hour, such as Windows vulnerabilities, Linux vulnerabilities, and Web vulnerabilities. N/A
    Vulnerability Status Trend Flow chart Today (Time Frame) The trend of the number of vulnerabilities in different states, such as unfixed and fixed, per hour. N/A
    Vulnerability Operation Distribution Doughnut chart Today (Time Frame) The distribution of operations on vulnerabilities, such as addition and verification. N/A
    Vulnerability Type Distribution Doughnut chart Today (Time Frame) The distribution of vulnerabilities of different types, such as Windows vulnerabilities, Linux vulnerabilities, and Web vulnerabilities. N/A
    Vulnerability Status Distribution Doughnut chart Today (Time Frame) The distribution of the latest states of vulnerabilities, such as unfixed, fixed, and fix failed.
    Notice If a vulnerability has multiple states, the latest state is used.
    N/A
    New Vulnerability Top10 Doughnut chart Today (Time Frame) The 10 most detected vulnerabilities. N/A
    Verify Vulnerability Top10 Doughnut chart Today (Time Frame) The 10 most verified vulnerabilities. N/A
    Fix Vulnerability Top10 Doughnut chart Today (Time Frame) The 10 most fixed vulnerabilities. N/A
    Vulnerability Client Distribution Top20 Table Today (Time Frame) The 20 hosts that have the most vulnerabilities. The table contains Client, Vulnerability Event, New, Verify, and Fix, and the number of vulnerabilities of different types. N/A
  • Alarm Center

    Provides a global overview of security alerts, which includes the trend, distribution, and states of new and cleared alerts.

    Chart Type Default time range Description Example
    Related Device Single value comparison Today (Time Frame)/Compared with Yesterday The number of unique hosts that have security alerts and the change compared to yesterday. 10.0, 0.01%
    New Alarm Single value comparison Today (Time Frame)/Compared with Yesterday The number of new alerts and the change compared to yesterday. 10.0, -0.01%
    Fix Alarm Single value comparison Today (Time Frame)/Compared with Yesterday The number of cleared alerts and the change compared to yesterday. 10.0, 0.01%
    High Level Alarm Single value comparison Today (Time Frame)/Compared with Yesterday The number of critical alerts and the change compared to yesterday. 10.0, -0.01%
    Alarm Operation Trend Flow chart Today (Time Frame) The trend of the number of operations on alerts, such as addition and verification, per hour. N/A
    Alarm Level Trend Flow chart Today (Time Frame) The trend of the number of different alert degrees, such as critical, suspicious, and warning, per hour. N/A
    Alarm Status Trend Flow chart Today (Time Frame) The trend of the number of alerts in different states, such as unfixed and fixed, per hour. N/A
    Alarm Operation Distribution Doughnut chart Today (Time Frame) The distribution of operations on alerts, such as addition and verification. N/A
    Alarm Level Distribution Doughnut chart Today (Time Frame) The distribution of alerts at different levels, such as critical, suspicious, and warning. N/A
    Alarm Status Distribution Doughnut chart Today (Time Frame) The distribution of the latest states of alerts, such as unfixed, fixed, and fix failed.
    Notice If an alert has multiple states, the latest state is used.
    N/A
    New Alarm Top10 Doughnut chart Today (Time Frame) The 10 most generated alerts. N/A
    Fix Alarm Top10 Doughnut chart Today (Time Frame) The 10 most cleared alerts. N/A
    Alarm Client Distribution Top20 Table Today (Time Frame) The 20 hosts that have the most alerts. The table contains Client, Alarm Event, New, Dealing, Serious, Suspicious, and Alarm Type. N/A