Logstail
Skip to Content
Logstail SIEM SOARAnalyticsDashboards

Dashboards

The Dashboards page provides visual analytics for Logstail data. Dashboards help users monitor security posture, operational trends, endpoint activity, compliance events, and other collected telemetry through charts, tables, counters, and visual panels.

Where to find it

Dashboards

Open the dashboards page from the main navigation.

Navigation path

Analytics
Dashboards

Application route

/dashboards

What This Page Is Used For

Use Dashboards to:

Review visual summaries

See high-level security and operational data.

Monitor SIEM activity

Track important events and trends.

Track trends

Analyze changes over time.

Inspect visual panels

Explore charts and visualizations.

Pivot into investigation

Move from dashboards into deeper analysis.

Create custom views

Build dashboards for specific workflows.

Save dashboard views

Reuse dashboards for repeated monitoring.

Share dashboards

Collaborate with analysts and responders.

Validate data sources

Ensure collectors send expected telemetry.

dashboards

Main View

Dashboards open as a full-page embedded dashboarding application. The page lists available dashboards in a table.

The dashboard list includes:

Search field
Create button
Dashboard title
Dashboard type
Description
Last updated timestamp
Actions column

The Create button is located in the top-right area of the Dashboards page.

Clicking Create opens a menu with these options:

Dashboard
Observability Dashboard

create-dashboard

Use Dashboard to create a standard analytics dashboard.

Use Observability Dashboard when creating an observability-focused dashboard view.

Common Dashboard Content

Dashboards can include:

Event counts
Authentication activity
Endpoint activity
Vulnerability or compliance views
File integrity monitoring data
Windows event analytics
Network or agent telemetry
SIEM rule and detection trends
Visualizations created from saved searches

How to Use the Dashboards Page

edit-dashboard

Create a Dashboard

Create an Observability Dashboard

create-observability-dashboard dashboard-in-list

Use observability dashboards when the view is focused on operational telemetry, service behavior, infrastructure health, or observability-style monitoring.

Time Range and Refresh

Dashboard results depend on the selected time window. Before making a conclusion, confirm the time range matches the use case.

Use shorter windows for active incident response and wider windows for trends, reporting, and historical review.

Refresh the dashboard after changing filters, time range, or underlying data sources.

Working With Pre-Built Dashboards

Pre-built dashboards help users start from known dashboard templates instead of creating every dashboard manually.

Pre-built dashboards are useful for common data sources such as Windows events, metrics, packets, SIEM telemetry, and other supported modules.

prebuilt-dashboards

Operational Workflows

SOC Monitoring

Investigation Pivoting

Compliance Review

Environment Validation

Dashboard Hygiene

Dashboards are operational assets. Keep them clean and useful by:

Removing outdated panels
Naming dashboards clearly
Grouping panels by use case
Avoiding overly broad dashboards that mix unrelated signals
Validating dashboards after index or data-source changes
Saving important dashboards with clear names
Exporting critical dashboard saved objects for backup or migration
Reviewing shared dashboards before deleting related visualizations or saved searches

Troubleshooting

Dashboard is empty

  1. 1

    Check the selected time range, data source, and whether the required agents or collectors are sending data.

  2. 2

    Confirm that the dashboard is using the correct index pattern.

  3. 3

    Confirm that related saved objects still exist.

Dashboard panels show errors

  1. 1

    The underlying saved objects, visualizations, index patterns, or fields may have changed.

  2. 2

    Review related visualizations and saved objects.

Values look incorrect

  1. 1

    Confirm the filters and time range.

  2. 2

    Validate the raw events in Analytics → Discover.

Save option is not visible

  1. 1

    The current user may not have permission to create or edit dashboards.

  2. 2

    If the dashboard is pre-built or managed, create a copy before editing when the platform provides that option.

Shared dashboard does not open

  1. 1

    Confirm that the recipient has access to the same Logstail stack, tenant, analytics space, and required permissions.

  2. 2

    If the dashboard was shared through Saved Objects, confirm that related visualizations, saved searches, and index patterns were also imported or already exist.

Imported dashboard has missing panels

  1. 1

    A dashboard can depend on visualizations, saved searches, maps, or index patterns.

  2. 2

    Export and import related objects together when moving dashboards between environments.

Dashboard controls differ from this guide

  1. 1

    Dashboards are embedded from the analytics application.

  2. 2

    Some controls can vary by configuration or version.

Best Practices

Use dashboards for monitoring

Use dashboards for monitoring and trend detection.

Validate raw data

Use Analytics → Discover for raw event validation.

Keep dashboards focused

Keep dashboards focused on a specific use case.

Name dashboards clearly

Save dashboard views with clear names.

Control sharing

Share dashboard views only with users who need access.

Use saved objects

Use Saved Objects export and import for backup, migration, or reusable dashboard sharing.

Review accuracy

Review dashboard accuracy after data model changes.

Check dependencies

Confirm related visualizations and index patterns before deleting saved objects.

Backup dashboards

Use saved objects to back up or migrate important dashboard content.

PageDescription
Pre-Built DashboardsInstall ready-made dashboards for supported collectors, modules, and data sources before opening them in Dashboards.
DiscoverValidate the raw events behind dashboard panels and investigate the data shown in charts or tables.
VisualizationsCreate or edit visual panels that can be added to dashboards.
Saved ObjectsExport, import, back up, or migrate dashboard objects and related visualizations.
Logstail AgentInstall and configure endpoint collection so dashboards have data to display.
ReportsGenerate report output from dashboards, saved searches, or analytics views.