In the Detection screen, the Detection score focuses on the incoming activity of Armor services. You can use these scores to determine if Armor is receiving the necessary data to perform useful security checks for your environment.
ForArmor Complete, these services are:
Filebeat (for Linux)
Winlogbeat (for Windows)
Widgets and Graph
This widget calculates a score based on:
Armor services that are collecting logs
Agents that are powered on
10 - 8
7 - 4
3 - 1
An event is any log that passes an Armor agent.
Malware Protection, File Integrity Monitoring, and Log and Event Management contain a subagent.
This widget displays data from the previous month.
This widget displays the percentage of agents that are receiving events. You can use this number to determine overall if your subagents are running properly.
Detection Score Trend
This graph displays the history of your detection scores.
The Detection Events table displays information for the past seven days. This table will update every day.
This column displays the date that Armor received the log.
This column displays the number of logs received for that day.
This column displays the type of log received from theTotal Eventscolumn. This column lists the subagent for the collected logs.
Content by Label
label in ("malware_protection","file_integrity_monitoring","vulnerability_scanning")