Skip to main content

Dashboard Guide

Navigate and use the CastellanAI security dashboard effectively.

Two Interfaces

Remember: The Customer Portal is for account management. The Security Dashboard (this guide) is for threat monitoring. Access it by clicking "Open Security Dashboard" from the Portal.


Dashboard Overview

The Security Dashboard provides real-time visibility into your security posture.

Main Components

ComponentDescription
Summary CardsKey metrics at a glance
Event TimelineRecent security events
Threat MapGeographic distribution of events
Agent StatusHealth of your deployed agents

Security Events

Viewing Events

Navigate to Security Events to see all captured events.

Event Details

Click any event to see detailed information:

FieldDescription
TimestampWhen the event occurred
SourceEndpoint that generated the event
CategoryEvent classification
SeverityCritical, High, Medium, Low

Filtering Events

Use filters to narrow down events:

FilterOptions
Date RangeSelect time period (last hour, day, week, custom)
SeverityCritical, High, Medium, Low
CategoryAuthentication, Process, Network, File, System
AgentFilter by source endpoint
SearchFull-text search across all fields

Exporting Events

  1. Apply your desired filters
  2. Click Export
  3. Choose format:
    • CSV - For spreadsheets
    • JSON - For automation/API
  4. Download the file

Alerts

Configuring Alerts

  1. Go to SettingsAlerts
  2. Click + New Alert Rule
  3. Define conditions:
ConditionDescription
Event TypeWhich event categories to monitor
Severity ThresholdMinimum severity to trigger
Occurrence FrequencySingle event or multiple occurrences
Time WindowHow long to track occurrences

Managing Alerts

ActionDescription
AcknowledgeMark an alert as seen (stops repeat notifications)
ResolveClose an alert after investigation
SnoozeTemporarily silence an alert (1 hour, 4 hours, 24 hours)
💡 Alert Best Practices
  • Start conservative - Begin with high-severity alerts only
  • Avoid alert fatigue - Don't over-alert on low-priority events
  • Use time windows - Require multiple occurrences before alerting
  • Review regularly - Tune rules based on false positive rate

AI Insights

The AI-powered analysis provides intelligent threat assessment:

Threat Scoring

Each event receives an automated risk score based on:

  • Event type and historical patterns
  • Context from correlated events
  • Known threat indicators
  • Behavioral analysis

Accessing AI Insights

Access AI insights from the Insights tab on any security event.


AI Chat

Use natural language to query your security data:

Example queries:
• "Show me failed logins in the last 24 hours"
• "What are the top threats this week?"
• "Explain this security event"
• "Are there any suspicious patterns from server-01?"

Learn more about AI Chat →


What's Next?

GuideDescription
Security ScoreUnderstand your security posture
Event MonitoringDeep dive into event analysis
Threat DetectionLearn about AI-powered detection