Risk Dashboard
The risk dashboard displays both current and historic risks based on the overall amount of PII data discovered on each endpoint. Risk is automatically updated each day when the endpoint completes a reindex of information.
Using the Risk Dashboard
Current Risk
The current risk grid displays the most recent risk for each endpoint. The numbers at the far left (Y-Axis) show the Raw Risk Score. The raw risk score is a sum of risk scores of all files containing risk. See Risk Score Calculation for details on how risk is calculated.
If you hover your cursor over an endpoint's stacked bar chart you will see the current risk name along with its overall score. You will also see a percentage breakdown of the type of risk and percentage Heureka's classification engine found during the last reported scan.
Last 30 Days (Historical)
Interrogate keeps a running history of total risk across a 30 day time period. This at-a-glance chart displays historical risk and makes it easier for you to monitor your risk.
The average line shows you what your average risk score is over the 30-day period. The trend line give you a general sense of whether your risk has been trending upward or downward over the 30-day period.
When you hover your cursor over a single day, you will see an average daily risk score for all endpoints that checked in.
Risk by Type
Interrogate breaks down risk by card type and social security. As you hover over the areas of the donut chart, you will see the percentage of card types and social security numbers. The percentage display represents the current risk.
Endpoint View
The bottom grid represents all of the endpoint services available to the system. You will note that there is a checkbox on the right side of each endpoint service. The endpoint view grid is interactive with the risk by type and current risk grid. In other words, as you select or deselect endpoints, the current and risk by type charts will interactively update themselves to display the information for the selected endpoints.
Create Search from Selected Endpoints
If you have selected specific endpoints and would like to run a search for file-level patterns, you may click on the create search from selected endpoints button in the upper right corner. You will be asked to select which job you would like the search to be placed in and then directed to the Search Criteria page. If you only want to see the patterns auto-detected by Interrogate, simply click the search and create a name.
Auto-Group
Interrogate automatically creates an endpoint group for you when using the create search from selected endpoints function. Your group name will be called "Dashboard Search <Date/Time>".