The equipment list : your machines
132 Views •A machine's detail page
120 Views •Alerts : the list of what was noticed
126 Views •Risk analysis : a score, and why
143 Views •Vulnerabilities : the updates that are missing
133 Views •The asset inventory : everything you own
90 Views •Activity : the running thread of what happens
119 Views •Checking a suspicious address, and outside intelligence
125 Views •The cybersecurity dictionary
159 Views •Defence : the blocked addresses
155 Views •Who is watching while you work
147 Views •Risk analysis : a score, and why
143 Views •The help centre and the explanation bubbles
140 Views •The crisis room: the button never to press
139 Views •Opening a support ticket
139 Views •Your three habits, and what comes next
136 Views •The dashboard : ten seconds to know
136 Views •Exclusions : silencing what is normal at your site
135 Views •My organisation : companies and licences
134 Views •Vulnerabilities : the updates that are missing
133 Views •Who it is for
133 Views •Creating your workspace and accepting the terms
133 Views •Companies : the administrative record
133 Views •Signing in : and what if I lost my password
132 Views •The equipment list : your machines
132 Views •Installing the agent on a machine
127 Views •Playbooks : ready-made responses
127 Views •Backups : verified, not just launched
127 Views •Activity : the running thread of what happens
"Activity report" page
Alerts show what was noticed. Activity shows what simply happens: logins, compliance scans, changed files, machines connecting or disconnecting.
It is the thread of everyday life. Most of the time nothing interesting occurs, and that is exactly what one wants to read.
Four counters and five filters
At the top: the total number of devices, how many are connected, how many are disconnected, and the number of events. Below, buttons to keep only one type: Alerts, Compliance, Files, Connections, or All.
Two further filters sharpen it: a severity threshold (medium and above, high and above, or critical only) and a field to follow one specific machine.
This is the page to open to answer "what happened on Tuesday?". It is not meant to be watched continuously. It is for retracing a specific sequence after the fact, and it does that very well.
The four kinds of event
Alert: something was noticed. Compliance: a settings scan ran. Files: a watched file moved. Connection: a machine connected or disconnected.
Each line links through to the record of the machine concerned, and compliance lines link to the matching good-practice reference. So you move from the event to its explanation without ever losing the thread.
An empty list on a recent workspace is normal: events arrive as soon as machines are connected. The screen says so itself.
In closing
Activity is the daily thread, and it is meant to be dull. You do not open it every day: you come back to it afterwards, to reconstruct a timeline when a question arises.
Commenting is not enabled on this course.