The Agentic SOC dashboard provides a centralized view of your security posture across cloud platforms, accounts, and services. Use the dashboard to monitor alerts, track log ingestion trends, and review defensive actions.
Metrics
-
Log on to the Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
-
(Optional) In the upper-right corner of the Dashboard page, click Time Range to set a query time range. By default, the dashboard displays data from the last 7 days.
-
View the statistics on the dashboard.
To explore a metric, click the data in a chart and then click Log Management to view detailed logs on the Log Search page.
Metric
Description
Global alert situation awareness
Gives you a comprehensive overview of security alerts to help you assess your overall security posture. Key metrics include:
-
Ingested logs: The total number of logs ingested into Agentic SOC.
-
Alert: The total number of alert records ingested into Agentic SOC. Data sources include:
-
Alerts from Web Application Firewall (WAF), Cloud Firewall, and Security Center.
-
Alerts from Agentic SOC predefined rules.
-
Alerts from Agentic SOC custom rules.
-
-
Alert: The number of alerts from Agentic SOC predefined rules.
-
Custom rule alerts: The number of alerts from Agentic SOC custom rules.
-
Monitored accounts: The number of accounts currently monitored by Agentic SOC, including Alibaba Cloud accounts and third-party cloud accounts.
Dashboard
Displays the top 5 log types with the highest ingestion volume.
Log source trend by product name
Shows the trend in the volume of ingested logs from different cloud products over time.
Alert source trend
Shows the trend in the number of alerts from different cloud products over time.
Distribution of alert source
Displays the distribution of alerts across different cloud products.
Top 5 alerts by type
Displays the top 5 alert types with the highest number of records.
Latest alerts list
Displays the most recent alert records. Alerts of the same type are aggregated into a single record.
Defensive action trend
Shows the trend of defensive actions.
-
alert: Generates an alert only.
-
drop: Blocks the traffic.
-
Set data refresh interval
When you open the Dashboard page, it displays a data snapshot from that moment. By default, the data does not refresh automatically.
-
Manual refresh: In the upper-right corner of the Dashboard page, click Refresh and then select Once.
-
Automatic refresh: In the upper-right corner of the Dashboard page, click Refresh and then select Automatic Refresh. Then, choose a refresh interval.
NoteThis setting reverts to its default (no refresh) if you reload the Dashboard page or navigate away from it.
Related topics
To learn how to analyze logs and view their fields, see Log Management.