Skip to content

Commit

Permalink
1.2 rn update (#370)
Browse files Browse the repository at this point in the history
* RN update

* adding widgets table

* table tweak

* table test

* table complete

* tweaks

* copy edits

* more edits

* typo
  • Loading branch information
jenjoe22 authored Feb 1, 2024
1 parent 8d4045f commit 6a6be9c
Show file tree
Hide file tree
Showing 3 changed files with 254 additions and 9 deletions.
3 changes: 3 additions & 0 deletions docs/.vscode/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"asciidoc.antora.enableAntoraSupport": true
}
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
== Create and Manage Dashboards

Track, visualize, share the metrics that matter most to you and your team with Prisma Cloud custom dashboards. Widgets with visual representations in various formats such as line and bar graphs and pie charts are available to track key metrics such as assets with the most urgent alerts and vulnerabilities, resource compliance trend charts and top risks to remediate. Share dashboard visualizations with your management team to quantify your progress in hardening your security posture.
Track, visualize, and share the metrics that matter most to you and your team with Prisma Cloud custom dashboards. Widgets with visual representations in various formats such as line and bar graphs and pie charts are available to track key metrics such as assets with the most urgent alerts and vulnerabilities, resource compliance trend charts, and top risks to remediate. Share dashboard visualizations with your management team to quantify your progress in hardening your security posture.

[.task]
[#createdashboards]
Expand All @@ -14,7 +14,7 @@ image::dashboards/add-dashboard.gif[]
. Select *Dashboards* from the Prisma Cloud administrative console. Make a note of the Prisma Cloud switcher mode you are on, for instance Cloud, Runtime or Application Security. Custom dashboards created in a specific mode are only viewable in that mode.
. Select *Add Dashboards* to create your custom dashboard.
. Give your new dashboard a unique identifier in the *Add Dashboard* drop-down. Select *Add New Dashboard* to confirm.
. Select *Edit Dashboard* and drag and drop widgets from the *Widget Selector* to your custom dashboard. You can also use the search bar to filter your search to locate the widgets with the data points required for your custom dashboard.
. Select *Edit Dashboard* and drag and drop widgets from the *Widget Selector* to your custom dashboard. You can also use the search bar to filter your search to locate the widgets with the data points required for your custom dashboard. Reference the table below to review specific widgets and their functions.
. Select *Add Filter* to further narrow your search by Time Range, Account Group or Cloud Account.
. Select *Done Editing* to save your changes.
+
Expand All @@ -23,6 +23,235 @@ image::dashboards/add-dashboard.gif[]
If the filters in the Edit Dashboard workflow conflict with the filters selected on any given Widget, the Widget filters will take precedence.
====

[cols="37%a,63%a"]
|===
|*Widget Name*
|*Description*

|*Adoption Progress*
|Depicts how well your team has been using the full set of Prisma Cloud capabilities. This percentage is a ratio of the number of tasks completed divided by the total number of tasks available to you. As your cloud footprint grows, use the Adoption Advisor to identify where to focus on your journey to strengthen your cloud security posture.

|*Alert Coverage*
|Provides a visualization of alerts coverage.

|*Alerts by MTTR*
|Displays alerts by severity and their mean time to resolution.

Note: If an alert is opened and resolved more than once a day, the latest resolution time is used for the MTTR calculation. A particular alert will be counted multiple times, if the same alert is resolved several times over multiple days.

|*Alerts by Resolution Reason*
|Displays the resolved alerts by their method of resolution. A particular alert will be counted multiple times, if the same alert is resolved several times over multiple days.

|*Alerts by Severity*
|Provides a visualization of alerts by Critical, High, Medium, or Low severity.

|*Anomalous Threats Detected*
|Anomalous Threats Detected are organized by UEBA and Network-based anomaly alerts and policies. The top row displays the number of threats detected for UEBA and Network for the past 30/60/90 days. The bottom row displays the number of enabled versus possible policies.

|*Assets by Classification*
|Provides a visualization of assets by cloud type, account name, region, or service type.

|*Asset Inventory Overview*
|Provides an overview of all assets and their alerts by severity.

|*Asset Trend*
|Provides the total number of assets and passing or failing assets for the last 90 days.

|*Assets with Urgent Alerts*
|Displays the count of critical and high severity risks detected for all policy violations such as Network, Anomaly, Audit Event, and Config policies by a tenant and the assets producing these alerts over a period of time. It also displays the Alert Remediation count that includes remediation action states of resolve, dismiss or snooze.

|*Code & Build Burndown and Inventory*
|Trend line of code issues over the last 30 days and Code & Build inventory snapshot of repositories.

|*Code Issues from Latest Branch Scans Over Time*
|A trend line of code issues over time from the latest branch scans.

|*Code Review Issues Over Time*
|A trend line of code issues over time tracking the number of issues blocked or scanned as part of VCS pull requests.

|*Code Vulnerabilities from Latest Branch Scans Over Time*
|Tracks latest vulnerabilities detected in branch scans.

|*Compliance Coverage*
|Top failing compliance standards.

|*Compliance Overview*
|Displays the overall health of cloud resources in an organization.

|*Compliance Trend*
|Compliance posture trend over time.

Note: If you select Time Range > Custom, only the Start Date day will be applied to the widget, not the hourly timestamp.

|*Deploy Burndown and Inventory*
|Trend line of urgent vulnerabilities over the last 30 days and Deploy inventory snapshot of registries and container images.

|*Discovered vs Secured Resources*
|Displays the extent to which the Defender is currently protecting your cloud environment. It shows the number of resources detected by Cloud Discovery as well as the number of Secured resources protected by deployed Defenders over a period of time.

|*Errors by Severity*
|Summary of all code issues by severity.

|*IaC Issues by Category*
|Total count of IaC misconfigurations by category.

|*Incident Burndown*
|Displays the critical and high severity alerts generated from Network, Anomaly, and Audit Event against the assets across your monitored cloud environments and your team’s progress on remediating these incidents. The remediation actions include the states of resolve, dismiss or snooze.

|*Incidents Burndown*
|Displays the last 30/60/90 days of critical and high severity alerts generated from Network, Anomaly, and Audit Event against the assets across your monitored cloud environments and your team’s progress on remediating these incidents. The remediation actions include the states of resolve, dismiss or snooze.

|*Internet Connected Assets by Traffic Location*
|Displays internet connected assets by region and provides a closer look at asset relationships.

|*Internet Exposed Unmanaged Assets*
|Top internet exposed unmanaged assets over time.

|*Latest Code Review Scans*
|Lists 1K latest code scans of VCS pull requests and CI/CD runs.

|*Most Common Code Issues by Policy*
|Displays the most common policy issues in code category of IaC Misconfigurations, secrets, and licensing. View the corresponding severity, issue count, and labels like *Has Fix* or *Custom Policy* to take informed business decisions.

|*Object Data Profile by Region*
|Displays object profiles such as Financial Information, Healthcare, PII and Intellectual Property across AWS Regions.

|*Open Alerts Over Time*
|Displays the number of alerts that were opened within a selected time period.

|*Policies by Severity*
|Provides a visualization of policies by severity and type.

|*Policies Drilldown*
|Provides the snapshot policy count for Incidents and Risks and the top 5 policies by alerts.

|*Policy Coverage*
|Provides a visualization of total enabled polices by type.

|*Prioritized Vulnerabilities*
|Prioritized vulnerabilities data over time.

|*Risk Burndown*
|Displays the number of critical and high severity risks detected using the Configuration policies on Prisma Cloud and your team’s progress on addressing these risks. The addressed actions include the states of resolve, dismiss or snooze.

|*Runtime Burndown and Inventory*
|Trend line of urgent incidents and attack paths over the last 30 days and Runtime inventory snapshot of cloud assets and workloads.

|*Security Events Stream*
|Latest 50 events detected in your cloud estate.

|*Top Assets by Role*
|Summarizes top open ports in your cloud environments and the percentage of traffic directed at each type of port.

|*Top Attack Path by Asset*
|Lists the top five attack paths by asset name, number of alerts, cloud service, and account name.

|*Top Attack Path By Policy*
|Provides the top five attack path policies that triggered an alert.

|*Top Code & Build, Deploy, Runtime Issues by Collection*
|Lists top issues by Team, Business Unit, and App using Collections.

|*Top Custom Alerts*
|Displays the top three custom policies by open alert count, highlighting the threats and misconfigurations you are catching through these policies.

|*Top CVSS Score Code Vulnerabilities*
|Lists code vulnerabilities with the highest CVSS score to help you discover and prioritize them using the Risk Factor, Severity and issue count.

|*Top Data Risks by Asset*
|Provides top five data risks by the assets they are connected to.

|*Top Data Risks by Policy*
|Provides the top five data risks by the policies they are connected to.

|*Top Exposures by Asset*
|Lists the top five exposures by asset name, number of alerts, cloud service, and account name.

|*Top Exposure by Policy*
|Lists the top five policies that triggered an exposure.

|*Top Identity Risks by Asset*
|Lists the top five identity risks by asset name, cloud type, service, account group and number of alerts.

|*Top Identity Risks by Policy*
|Lists the top five policies that triggered an IAM alert.

|*Top Impacting Vulnerbilities*
|Top Impacting Vulnerbilities data over time.

|*Top Incidents & Risks*
|Lists the top five incidents and risks by policy type and number of alerts.

|*Top Incidents & Risks by MITRE ATT&CK*
|Lists the top five incidents and risks mapped to the MITRE Framework.

|*Top Incidents by Asset*
|Lists top five incidents by asset name, number of alerts, cloud service, and account name.

|*Top Incident By Policy*
|Lists the top five policies that triggered an alert.

|*Top Insecure Repositories*
|Top seven repositories with the highest Critical and High severity issue count.

|*Top Internet Trafficked Assets by Traffic Type*
|Displays top Internet connected assets by traffic type.

|*Top Misconfigurations by Asset*
|Lists top five misconfigurations by asset name, number of alerts, service, and account name.

|*Top Misconfigurations by Policy*
|Lists the top five policies that triggered a misconfiguration.

|*Top Non-Compliant Package Licenses*
|Identifies the frequently occurring non-compliant package licenses within repositories.

|*Top Publicly Exposed Objects By Data Profile*
|Displays the five publicly exposed objects with Data Profiles of Financial Information, Healthcare, PII and Intellectual Property.

|*Top Risks from Unmanaged Assets*
|Lists top risks from unmanaged assets over time.

|*Top Vulnerable Hosts*
|Lists the top five vulnerable hosts.

|*Top Vulnerable Images*
|Lists the top five vulnerable images.

|*Total Objects*
|Displays the total number of objects discovered in all your S3 storage buckets.

|*Total Resources*
|Provides a visualization of total resources.

|*Total Urgent Issues*
|Provides a tally of urgent issues grouped by Incidents, Exposures, Misconfigurations, Identity, and Data Risks.

|*Unamanaged and Managed Asset Trend*
|Tally of unamanaged and managed asset data over time.

|*Unamanaged Exposed Assets by Country*
|Tally of exposed assets by country over time.

|*Urgent Alerts*
|Provides a visualization of Critical, and High severity incidents.

|*Urgent Vulnerabilities*
|Provides a visualization of Critical, and High severity vulnerabilities.

|*VCS Pull Requests Over Time*
|Analyzes the impact of Enforcement rules on new code deliveries. Observe the adoption of secure coding practices over time, including the reduction of failed PRs.

|*Vulnerabilities Overview*
|Top vulnerabilities data over time.

|*Vulnerabilities Trends*
|Displays the vulnerabilities discovered and resolved over time across images, hosts, containers and functions for the impacted resources.

|*Vulnerability Impact by Stage*
|Displays vulnerability impact data over time.

|===

[#managewidgets]
[.task]
Expand All @@ -32,30 +261,30 @@ After you have added any widget to your dashboard you have multiple options to f

[NOTE]
====
The data you view in any given widget may vary based on the permissions associated with your role.
The data you view in any given widget varies based on the permissions associated with your role.
====

[.procedure]
. Select the *Toggle Table* icon to convert the data visualization in a widget to a table. You can also choose the *Full Screen* button to expand widget dimensions to the maximum size.

. You can edit the views in any widget once you have added them to your custom dashboard. Follow these steps to edit a widget:

.. Select the *Edit* button from the Widget menu. The editable options vary from widget to widget and may include chart name, chart variable such as number of vulnerabilities listed, data source for compliance trends over time etc.
.. Select the *Edit* button from the Widget menu. The editable options vary from widget to widget and may include chart name, chart variable such as number of vulnerabilities listed, data source for compliance trends over time and more.

.. Select the *Clone* button to duplicate the widget. This generates a cloned widget.
.. Select the *Clone* button to duplicate the widget.

.. Choose the *Delete* button to delete any widget from a dashboard.
.. Select the *Delete* button to delete any widget from a dashboard.


[#managedashboards]
[.task]
=== Manage Dashboards

Follow the steps below to manage your created dashboards.
Follow the steps below to manage the dashboards you've created.

[.procedure]
. Select *Manage Dashboards* to clone or delete any existing dashboard.
.. Select the dashboard you wish to delete from the drop-down list and choose clone or delete.
.. Select the dashboard you want to delete from the drop-down list and select *Clone* or *Delete*.
.. Select the action button on any dashboard to easily copy or delete the selected dashboard.
+
[NOTE]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,19 @@ tt:[*24.1.2*]

|Prisma Cloud’s Latest Events tracker now provides redirections on the events from all phases of the Code Build Deploy Run (CBDR) cloud deployment lifecycle. Select any event from *Home > Dashboards > Code to Cloud > Latest Events* to immediately take action and investigate the risk or incident. Learn more about optimizing Prisma Cloud https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/dashboards-code-to-cloud[Dashboards].

|tt:[Update] *Code to Cloud Dashboard*
//RLP-88548

tt:[*Secure the Infrastructure*]

tt:[*24.1.2*]

|Prisma Cloud's *Dashboards > Add Dashboard > Widget Selector* now includes two additional widgets to help you easily report on your organization's efficiency in responding to alerts. Widgets are currently available to System Administrators and include:

* Alerts by MTTR - Displays alerts by severity and their mean time to resolution.
* Alert by Resolution Reason - Displays the resolved alerts by their method of resolution.
Learn more about leveraging these widgets to https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards[create] your own custom dashboards.

|*Send Ad hoc Alert Notifications to Email and Slack*
//RLP-106064
Expand Down Expand Up @@ -98,7 +111,7 @@ tt:[*Secure the Infrastructure*]

tt:[*24.1.1*]

|*Prisma Cloud > Dashboards > Widget Selector* now includes eight additional https://docs.prismacloud.io/en/enterprise-edition/content-collections/get-started/adoption-advisor#id0356c4cc-e4f1-43e2-8848-3f6cd7e4cd60[widgets] to help you create https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards[customized dashboards] to track your organization’s key metrics. Widgets include:
|Prisma Cloud's *Dashboards > Add Dashboard > Widget Selector* now includes eight additional https://docs.prismacloud.io/en/enterprise-edition/content-collections/get-started/adoption-advisor#id0356c4cc-e4f1-43e2-8848-3f6cd7e4cd60[widgets] to help you create https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards[customized dashboards] to track your organization’s key metrics. Widgets include:

* Adoption Progress
* Assets with Urgent Alerts
Expand Down

0 comments on commit 6a6be9c

Please sign in to comment.