Skip to content

Using the Dashboard

The LT Auditor MP dashboard is the main screen after logging in. It provides a real-time overview of activity across your monitored environment, giving administrators and analysts a quick way to assess system health, spot unusual behavior, and navigate to more detailed views. This article covers the dashboard layout and how to navigate the main interface — for detailed guidance on searching and filtering log data see the Searching & Filtering Events article.


Accessing the dashboard:

The dashboard loads automatically after login. To return to the dashboard at any time click the Home icon or the LT Auditor MP logo in the main navigation.


Dashboard overview:

The dashboard is organized into several key areas providing at-a-glance visibility across your monitored environment:

Section Description
Activity Trend A graph showing audit event volume over time — helps identify spikes or drops in activity
Top Users The most active users by event count across monitored environments
Top Objects The most frequently accessed or modified objects such as files, directories, or accounts
Top Servers The most active servers by event count
Top Operations The most frequently occurring event types across all monitored sources
Alert Status A summary of current open alerts requiring attention
Last Refresh Timestamp showing when the dashboard data was last updated

[Your administrator should add a labeled screenshot of the dashboard here to help users orient themselves to the layout in your deployment.]


Main navigation:

The main navigation menu provides access to all platform modules:

Module Purpose
Define Set up audit environments and log categories
Configure Set up receivers and transformation rules
Manage Create and manage audit filters and alert rules
Reports Create, schedule, and manage reports
View Browse and search audit log data in real time
Comply Manage compliance frameworks and monitor compliance status
Admin Manage users, roles, collector configuration, and system settings

Navigating from the dashboard:

The dashboard is designed as a starting point for investigation rather than a detailed monitoring tool. Use the dashboard to identify areas requiring attention, then navigate to the relevant module for deeper analysis:

If you see… Navigate to…
An alert in the Alert Status section Alerts → Active Alerts to review and investigate
A spike in the Activity Trend graph View → select the relevant environment to investigate the underlying events
An unexpected top user or operation View → filter by that user or operation to see full detail
A compliance status concern Comply → Compliance Dashboard to review framework status
A service or agent health issue Admin → Collector Details or the relevant module’s client page

Customizing the dashboard view:

  1. Use the date range selector at the top of the dashboard to adjust the time period displayed
  2. Click on any metric or chart element to drill down into the underlying event data
  3. Use the environment selector if available to filter the dashboard to a specific monitored environment
  4. Click Refresh to manually update the dashboard with the latest data

Understanding the activity trend graph:

The activity trend graph displays event volume over the selected time period. Use it to:

  • Identify spikes — sudden increases in event volume may indicate a security incident, a misconfiguration generating excessive events, or an attack
  • Identify drops — sudden decreases may indicate a collection or connectivity issue with a module or agent
  • Establish baselines — regular review of the activity trend helps build a sense of normal traffic patterns, making anomalies easier to recognize over time

If you notice an unexpected spike or flatline navigate to View to investigate the underlying events in more detail.


Switching between monitored environments:

If your deployment monitors multiple environments such as Windows, Linux, eDirectory, and Azure, you can switch between environment-specific views from the dashboard:

  1. Use the environment selector on the dashboard or navigate directly to View
  2. Select the relevant environment
  3. The data updates to reflect activity for the selected environment

[Your administrator should document the specific environments configured in your deployment and what each one covers so users know where to look for specific types of activity.]


Best practices:

  • Check the dashboard at the start of each shift or workday as a quick health check before moving on to other tasks
  • Investigate any open alerts visible in the Alert Status section before beginning other monitoring activities
  • Use the activity trend graph to build familiarity with normal traffic patterns in your environment — anomalies become easier to spot with experience
  • If the Last Refresh timestamp is significantly behind the current time check that all collection module services and agents are running correctly
  • Use the dashboard as a starting point for investigation rather than a definitive source — always navigate to View for detailed event analysis

[Your administrator should add a labeled screenshot of the dashboard and document any environment-specific widgets or customizations relevant to your deployment.]