The equipment list : your machines
138 Views •A machine's detail page
125 Views •Alerts : the list of what was noticed
126 Views •Risk analysis : a score, and why
147 Views •Vulnerabilities : the updates that are missing
139 Views •The asset inventory : everything you own
101 Views •Activity : the running thread of what happens
128 Views •Checking a suspicious address, and outside intelligence
128 Views •The cybersecurity dictionary
162 Views •Defence : the blocked addresses
158 Views •Who is watching while you work
147 Views •Risk analysis : a score, and why
147 Views •The crisis room: the button never to press
145 Views •Exclusions : silencing what is normal at your site
144 Views •The help centre and the explanation bubbles
143 Views •Opening a support ticket
142 Views •Companies : the administrative record
142 Views •Your three habits, and what comes next
142 Views •The dashboard : ten seconds to know
141 Views •My organisation : companies and licences
139 Views •Vulnerabilities : the updates that are missing
139 Views •The equipment list : your machines
138 Views •Creating your workspace and accepting the terms
137 Views •Who it is for
136 Views •The insurability score : answering insurers
135 Views •Playbooks : ready-made responses
134 Views •Signing in : and what if I lost my password
134 Views •Backups : verified, not just launched
134 Views •Activity : the running thread of what happens
"Activity report" page
Alerts show what was noticed. Activity shows what simply happens: logins, compliance scans, changed files, machines connecting or disconnecting.
It is the thread of everyday life. Most of the time nothing interesting occurs, and that is exactly what one wants to read.
Four counters and five filters
At the top: the total number of devices, how many are connected, how many are disconnected, and the number of events. Below, buttons to keep only one type: Alerts, Compliance, Files, Connections, or All.
Two further filters sharpen it: a severity threshold (medium and above, high and above, or critical only) and a field to follow one specific machine.
This is the page to open to answer "what happened on Tuesday?". It is not meant to be watched continuously. It is for retracing a specific sequence after the fact, and it does that very well.
The four kinds of event
Alert: something was noticed. Compliance: a settings scan ran. Files: a watched file moved. Connection: a machine connected or disconnected.
Each line links through to the record of the machine concerned, and compliance lines link to the matching good-practice reference. So you move from the event to its explanation without ever losing the thread.
An empty list on a recent workspace is normal: events arrive as soon as machines are connected. The screen says so itself.
In closing
Activity is the daily thread, and it is meant to be dull. You do not open it every day: you come back to it afterwards, to reconstruct a timeline when a question arises.
Commenting is not enabled on this course.