The Top 20 High Risk Users chart shows the top 20 high risk users and their respective number of high risk events.
To access the Top 20 High Risk Users chart, go to .
Click on the dashboard to view drill-down information.
The drill-down table shows more detailed information about each user, including:
- IP address
- Target application
- IP reputation
Scroll to the right to see additional columns. Only events that have triggered a specific
risk model, such as geovelocity anomaly, or have an aggregated risk score of
HIGH
are shown. The aggregated risk score is determined by the selected
risk policies in the Policy Name list.
Scroll to the right to see additional columns. For use of the filtered search bar, see Filtered searching.
For a description of the table columns, see Monitored risk data.
You can click a column header to sort the results by that value. Results are sorted by the Time column by default, with the most recent entries listed first.
Left hand filters:
- To filter risk policies to be included in the map, use the Policy
Name list.
You can select multiple policies.
- To filter the data by specific users, use the User Name
list.
All users are selected by default.
Note:The User Name selection only affects the drill down table.
- You can use the slider to show data from the current day, previous week, previous
month, or previous six months.
To show data from a custom time period, use the Date Range filter.