Events/min 847
--:-- UTC
Events / Min
847
↑ 14% above baseline
Active Alerts
0
Current merged alert queue
Open Investigations
0
Canonical and analyst-created cases
Generated Samples (7d)
0
Rolling centralized fact stream
0
Log Events Indexed
0
Detection Rules
0
Total Investigations
0
Investigations Closed
5
Reports Generated
0
Sources Online
Log Ingest Volume - Last 24 Hours Click a bar to filter investigations by ingest window
Normal
Incident spike
Recent Alerts View all →
Ingest Sources 7-day modeled event volume
SourceEventsShare
 Microsoft Entra ID142,84732%
 Exchange Online↑ spike98,23322%
 CrowdStrike Falcon87,44120%
 Palo Alto NGFW76,22917%
 Protective DNS65,88215%
 SecIntel VPN Gateway43,11710%
 Defender for Cloud Apps31,0047%
 SecIntel SCADA Monitorreduced28,7736%
MITRE ATT&CK Coverage 28 active rules →
Initial Access
3
Execution
2
Persistence
3
Priv. Escalation
2
Credential Access
2
Discovery
2
Lateral Movement
1
Collection
2
Exfiltration
3
Impact
2
ICS / OT
4
Open Investigations View all →
Mock SIEM - simulation environment for foyl Learn. Open a lab or scenario to get started.