ThreatStream Overview Dashboard

When accessing the Default dashboard page for the first time, you land on the ThreatStream Overview dashboard, which is one of the dashboards available to all Anomali platform users out of the box. The ThreatStream Overview dashboard is your default primary dashboard.

If you designate some other dashboard as your primary, the ThreatStream Overview dashboard can be found in the Library (Dashboard > Library)

The ThreatStream Overview dashboard is the hub of proactive threat detection for your organization on ThreatStream. The dashboard includes panels that provide an overview of the intelligence available to you in ThreatStream. It also displays any alerts that require an immediate action. Furthermore, the ThreatStream Overview dashboard enables you to drill down on intelligence for deeper analysis.

Below is an example of the ThreatStream Overview dashboard.

Share the dashboard by copying the dashboard URL or exporting it in JSON format. For details, see Sharing Dashboards or Sharing Dashboards (Classic UI) if you use the classic UI.
Add the dashboard to the list of favorites. All your favorite dashboards can be found in the Bookmarked section of the Dashboard menu.
Designate the current dashboard as your primary dashboard. The setting is saved per user, so each user in the organization can designate their own primary dashboard. The name of the primary dashboard appears as the first item in the Dashboard menu.

Select a time range for the data displayed on the dashboard. You can select an absolute time range or a relative time range. By default, data for the last 7 days is displayed.

Select a time range for refreshing the dashboard. Select Off if you don’t want to refresh the dashboard. Click to force dashboard refresh.

Clone the dashboard. For details, see Cloning Dashboards or Cloning Dashboards (Classic UI) if you use the classic UI.

Export the dashboard in PDF format. For details, see Exporting Dashboards in PDF Format or Exporting Dashboards in PDF Format if you use the classic UI.

ThreatStream Overview Dashboard Panels

The following table contains the list of all panels available on the ThreatStream Overview dashboard.

Panel Description
Total # of Observables

Number of observables added during the time range selected for the dashboard.

Your Total Contribution
  • Number of observables added by your organization during the selected time range. Sources include imports, feeds configured by your organization, or TAXII feeds.
  • Sightings Number of observables from the selected time range that triggered alerts in your integrated destinations.
    Total Community Contribution
  • Number of observables to which you have access that were contributed by other organizations.
  • # of False Positives Filtered Number of observables to which you have access that were reported as false positive.
    Last Indicator Received
  • Time elapsed since the most recent observable to which you have access was added to ThreatStream.
  • Sources

    View statistics on observables added to ThreatStream via your organization, private feeds, and curated open source feeds. Hover over a source to view the source statistics over the specified period of time.

    • Overall: Total number of observables provided by the source.
    • This Period: Number of observables provided by the source during the selected time range.
    • % Change: Ratio of observables provided by the source during the selected time range over the overall total.
    • # of False Positives: Observables from the source that have been identified as false positive.
    Imports

    Total number of import jobs created over the specified period of time.

    Threat Model Total number of threat model entities created over the specified period of time.
    Investigations Total number of investigations started over the specified period of time.
    Trusted Circles Total number of trusted circles created over the specified period of time.
    Latest Activity

    View the 10 most recent notifications on ThreatStream activity. Notifications are displayed when:

    • Import sessions created by your organization or trusted circles of which you are a member are approved. Click the activity to view the import session.
    • Import sessions created by your organization are ready for review and you have the Approve Import user privilege. Click the activity to view the import session.
    • Observables to which your organization has access are imported or updated.
    • Threat model entities to which your organization has access are created, published, or updated. Click the activity to view the threat model entity.
    • Investigations owned by your organization or accessible via trusted circles are updated. Click the activity to view the investigation.
    • Submissions are made to an organization Import or Phishing mailbox. Links to associated import sessions, Threat Bulletins, or investigations are included in the activity. Unsuccessful submissions are also displayed.
    My Alerts

    View statistics on recently triggered rules and corresponding automated actions taken by ThreatStream.

    • No Actions Taken: Number of matches during the selected time period for which no actions were configured.
    • Tagged With Terms: Number of matches that resulted in intelligence being tagged with configured terms.
    • Added to Investigation: Number of matches resulting in intelligence being added to investigations.
    • Added to Threat Model: Number of matches resulting in intelligence being added to threat model entities.

    You can click any of the rule categories to view a list of triggered rules in a pop up window.

    All ThreatStream Overview dashboard panels have the management menu allowing you to take the following actions:

    • Open a panel query in Event Search

    • View a full-screen version of a panel

    • Share a panel with other ThreatStream users in your organization.

    • Inspect panel data

    • Refresh panel data

    For details, refer to Managing Dashboard Panels or Managing Dashboard Panels (Classic UI) if you use the Classic UI.