9 min read Updated May 12, 2026

Dashboard Guide

The Tamandua Sentinel Dashboard provides real-time visibility into your security posture across all managed endpoints. This guide covers dashboard widgets, metrics interpretation, and customization options.

Dashboard Overview

The dashboard is your primary interface for monitoring endpoint security health and threat activity.

[Screenshot: Full dashboard view with all widgets visible]

Overview Widgets

Security Posture Widget

Displays your organization's overall security health score based on:

  • Agent Coverage: Percentage of endpoints with active agents
  • Detection Coverage: Endpoints with current detection rules
  • Vulnerability Exposure: Known vulnerabilities across endpoints
  • Compliance Score: Adherence to security policies

Score RangeStatusDescription
90-100ExcellentOptimal security posture
75-89GoodMinor improvements recommended
50-74FairAttention required on key areas
Below 50CriticalImmediate action required

[Screenshot: Security Posture widget showing score breakdown]

Active Threats Widget

Real-time display of detected threats:

+------------------------------------------+
|  ACTIVE THREATS              Last 24h    |
+------------------------------------------+
|  Critical     [===]           3          |
|  High         [======]        8          |
|  Medium       [=========]    15          |
|  Low          [============] 24          |
+------------------------------------------+
|  Total Active: 50    |    Resolved: 127  |
+------------------------------------------+

Click any severity level to filter the Alerts view.

Agent Status Widget

Overview of agent health across your environment:

StatusIconDescription
OnlineGreen circleAgent reporting normally
DegradedYellow circleAgent reporting but with issues
OfflineRed circleAgent not reporting
IsolatedBlue shieldAgent network-isolated
PendingGray clockAgent awaiting deployment

[Screenshot: Agent Status widget with status breakdown pie chart]

Top Endpoints Widget

Lists endpoints with the most alert activity:

EndpointAlerts (24h)StatusRisk
WORKSTATION-04223OnlineHigh
SERVER-PROD-0118OnlineHigh
LAPTOP-SALES-0712OnlineMedium

Click an endpoint to view detailed agent information.

Alert Trends

Alert Volume Chart

Interactive time-series chart showing alert volume over time.

Time Range Options:
  • Last 1 hour
  • Last 24 hours (default)
  • Last 7 days
  • Last 30 days
  • Custom range

Grouping Options:
  • By severity
  • By category
  • By detection source (YARA, Sigma, ML, Behavioral)

[Screenshot: Alert volume chart with severity breakdown over 7 days]

Alert Breakdown

Pie chart visualization of alerts by:

  • Category: Malware, Suspicious Activity, Policy Violation, etc.
  • Source: Detection method that triggered the alert
  • Status: Open, Investigating, Resolved, Suppressed

Trend Indicators

Each metric displays a trend indicator:

  • Upward Arrow (Red): Increase from previous period (concerning)
  • Downward Arrow (Green): Decrease from previous period (improving)
  • Flat Line: No significant change

Example:

Critical Alerts: 5  [Down Arrow] -40% vs last week
Open Investigations: 12  [Up Arrow] +20% vs last week

Agent Status

Agent Health Summary

The Agent Health widget provides at-a-glance status:

+------------------------------------------+
|  AGENT HEALTH                            |
+------------------------------------------+
|  [============================] 94%      |
|  1,245 / 1,325 agents healthy            |
+------------------------------------------+
|  Online:    1,245  |  Isolated:    15    |
|  Degraded:     45  |  Pending:      5    |
|  Offline:      15  |                     |
+------------------------------------------+

Agent Version Distribution

View agent version deployment status:

VersionCountPercentageStatus
2.5.098074%Current
2.4.228021%Supported
2.3.1655%Outdated

[Screenshot: Agent version distribution chart with update recommendations]

Platform Distribution

Breakdown of agents by operating system:

  • Windows: Windows 10/11, Windows Server 2016/2019/2022
  • Linux: Ubuntu, RHEL, CentOS, Debian
  • macOS Preview: Monterey, Ventura, Sonoma lab endpoints only

Recently Deployed

List of recently deployed or updated agents:

AgentPlatformVersionDeployed
LAPTOP-NEW-001Windows 112.5.02 min ago
SERVER-WEB-03Ubuntu 22.042.5.015 min ago
MAC-LAB-012macOS 14.2 Preview2.5.0-preview1 hour ago

MITRE ATT&CK Coverage

Coverage Matrix

Interactive MITRE ATT&CK framework heatmap showing:

  • Green: Techniques with active detection rules
  • Yellow: Partial coverage (some subtechniques covered)
  • Red: No detection coverage
  • Blue: Techniques detected in your environment (last 30 days)

[Screenshot: MITRE ATT&CK matrix heatmap with coverage visualization]

Tactic Overview

TacticTechniques CoveredTotal TechniquesCoverage
Initial Access8989%
Execution111479%
Persistence171989%
Privilege Escalation121392%
Defense Evasion354283%
Credential Access141782%
Discovery253181%
Lateral Movement8989%
Collection151788%
Command and Control141688%
Exfiltration8989%
Impact121392%

Recent Detections by Technique

Techniques observed in your environment:

TechniqueIDDetections (7d)Last Seen
Process InjectionT1055455 min ago
Scheduled TaskT10533212 min ago
Registry Run KeysT1547.001281 hour ago
PowerShellT1059.0011562 min ago

Click any technique to view related alerts.

Coverage Gaps

Identifies techniques without detection coverage that have been observed in threat intelligence:

TechniqueIDThreat Groups UsingRisk
DLL Side-LoadingT1574.002APT29, APT41High
TimestompingT1070.006MultipleMedium

Customization

Widget Management

Adding Widgets

  1. Click Customize in the dashboard toolbar
  2. Click Add Widget
  3. Select widget type from available options
  4. Configure widget settings
  5. Click Save

[Screenshot: Widget gallery showing available widget types]

Available Widget Types

CategoryWidgets
OverviewSecurity Posture, Active Threats, Alert Summary
AgentsAgent Status, Version Distribution, Platform Breakdown
AlertsAlert Trends, Alert Volume, Top Alerts
DetectionMITRE Coverage, Detection Rules, ML Model Performance
PerformancePipeline Latency, Query Performance, System Health
CustomSaved Search, Custom Query, External Data

Removing Widgets

  1. Hover over the widget
  2. Click the More Options (three dots) menu
  3. Select Remove Widget

Resizing and Repositioning

  • Drag: Click and drag the widget header to reposition
  • Resize: Drag the widget corner to resize

Widgets snap to a grid system for consistent alignment.

Dashboard Layouts

Creating a Layout

  1. Arrange widgets as desired
  2. Click Customize > Save Layout
  3. Enter a layout name
  4. Optionally set as default

Layout Templates

Pre-built layouts for common use cases:

TemplateDescription
SOC OverviewHigh-level security metrics for SOC managers
Threat HuntingDetection and MITRE-focused view
Incident ResponseAlert and investigation-centric layout
ExecutiveSummary metrics for leadership reporting
Agent OperationsEndpoint health and deployment focus

[Screenshot: Layout template selection dialog]

Sharing Layouts

Share layouts with team members:

  1. Click Customize > Share Layout
  2. Select users or roles
  3. Choose permission level (View/Edit)
  4. Click Share

Time Zone Configuration

Set your preferred time zone for all dashboard displays:

  1. Click your user avatar
  2. Select Preferences
  3. Choose your time zone
  4. Click Save

All timestamps will display in your selected time zone.

Refresh Settings

Configure dashboard auto-refresh:

SettingIntervalUse Case
Real-time5 secondsSOC monitoring
Frequent30 secondsActive investigation
Standard5 minutesGeneral use
ManualDisabledReport creation

Enable/disable auto-refresh using the toggle in the dashboard toolbar.

Color Themes

Customize severity colors for accessibility:

SeverityDefaultDeuteranopiaCustom
CriticalRedPurpleConfigurable
HighOrangeBlueConfigurable
MediumYellowCyanConfigurable
LowGreenGrayConfigurable

Dashboard Filters

Global Filters

Apply filters that affect all dashboard widgets:

  • Time Range: Limit data to specific time period
  • Agent Group: Filter to specific endpoint groups
  • Organization: Filter by organization (MSSP mode)
  • Tags: Filter by custom tags

[Screenshot: Global filter bar with multiple filters applied]

Widget-Level Filters

Individual widgets can have additional filters:

  1. Click the filter icon on the widget
  2. Configure widget-specific filters
  3. Click Apply

Widget filters combine with global filters.

Saved Filters

Save frequently used filter combinations:

  1. Configure desired filters
  2. Click Save Filter
  3. Enter a name
  4. Access saved filters from the filter dropdown

Exporting Data

Widget Export

Export individual widget data:

  1. Click the More Options menu on the widget
  2. Select Export
  3. Choose format (CSV, JSON, PDF)

Dashboard Export

Export the entire dashboard as a report:

  1. Click Export in the dashboard toolbar
  2. Select format:
  • PDF: Formatted report with visualizations
  • PNG: Dashboard screenshot
  1. Configure options (date range, branding)
  2. Click Export

Scheduled Reports

Automate dashboard exports:

  1. Navigate to Reports > Scheduled
  2. Click New Schedule
  3. Select dashboard and format
  4. Configure schedule (daily, weekly, monthly)
  5. Add recipients

Performance Considerations

Large Deployments

For environments with 10,000+ agents:

  • Use widget pagination where available
  • Leverage agent groups for filtered views
  • Consider time range limitations for heavy queries
  • Enable query caching in Settings

Dashboard Load Time

If dashboard load time exceeds expectations:

  1. Review widget count (recommend max 12)
  2. Check time range filters (shorter ranges load faster)
  3. Verify agent group filters are applied
  4. Contact support if issues persist

Next Steps