Skip to main content
Skip table of contents

Monitor Hosts

In addition to responding to incidents, analysts can also monitor and research activities associated with specific hosts.

To monitor hosts:

  1. In the main menu, click the Hosts tab, and then click Highlighted Hosts.
    The Highlighted Hosts screen appears.

    Highlighted hosts are organized into three columns:

    Column Name

    Column Description

    Notable HostsHosts that have the highest score.
    Watched HostsHosts manually marked as watched because of a potential compromise or because they have exhibited suspicious behavior.
    Critical HostsHosts who need to be monitored more closely because they are critical to the organization.
  2. To view the details of a specific host, click the Host ID.
    The Host Details screen appears.
    The table below lists the sections displayed on the Host Details screen with the location and a brief description.

    Section

    Location

    Description

    Host Directory and Host ScoreUpper left-sideContains details about the host. Also shows the host's LogRhythm NDR severity score and number of incidents associated with the host.
    Host Score Time ChartUpper right-sideDisplays the host's score progression over time.
    Host ActivityLower half

    Contains a graph of the host's security events over time and a searchable list of the host's activity.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.