WatchGuard EDR Security Dashboard

Applies To: WatchGuard EDR

The WatchGuard EDR Security dashboard shows an overview of the security status of the network for a specific time period. Several tiles show important information and provide links to more details.

The Status page includes similar dashboards and lists to those available in WatchGuard EPDR, but does not require a Web Access dashboard. WatchGuard EDR does not include antivirus.

Screen shot of the WatchGuard EDR Security dashboard

Time Period Selector

The dashboard shows information for the time period selected by the administrator in the drop-down list at the top of the Status page.

Screen shot of the Time Selector drop-down list

You can select the following time periods:

  • Last 24 hours
  • Last 7 days
  • Last month
  • Last year

Some tiles do not show information for the last year. If last year information is not available for a specific tile, a notification is displayed.

The Security dashboard includes these tiles:

Click a tile to view detailed information.

Status Icons

The icons in the Advanced Protection, Antivirus, Updated Protection, and Knowledge columns indicate their status:

  • The installing icon — Installing
  • The Enabled icon — Enabled
  • The Disabled icon — Disabled
  • The Error icon — Error
  • The No License icon — No License
  • The Not Available Icon — Not Available
  • The Pending Restart icon — Pending Restart

Protection Status

The Protection Status tile shows:

  • Computers where WatchGuard EDR is working properly
  • Computers with errors or problems installing or running the product

Screen shot of the Protection Status tile

Click the tile to open the Computer Protection Status list.

Screen shot of the Computer Protection Status list

To filter the Computer Protection Status list:

  1. Click Filters.
  2. Select the Computer Type.
  3. Specify platform, connection, and protection parameters.
  4. Select the Protection Status.
  5. Select the Isolation Status.
  6. Click Filter.

WatchGuard EDR does not support Android devices.

Offline Computers

The Offline Computers tile shows the number of computers that have not connected to the cloud for a number of days.

Screen shot of the Offline Computers tile

Click the tile to see details of the computers that might be susceptible to security problems and require attention.

Screen shot of the Offline Computers list

Outdated Protection

The Outdated Protection tile shows the number of computers with a signature file that is more than three days older than the latest released file. It also shows the computers with an antivirus engine that is more than seven days older than the latest released engine.

  • Protection: For at least seven days, the computer has had a version of the antivirus engine older than the latest released engine.
  • Knowledge: The computer has not updated its signature file for at least three days.
  • Pending Restart: The computer requires a restart to complete the update.

Screen shot of the Outdated Protection tile

Click the progress bar in the tile to see the list of computers associated with each status:

  • Computers with out-of-date protection
  • Computers with out-of-date knowledge
  • Computers pending restart

Programs Allowed by the Administrator

These tiles show the number of programs allowed by the administrator which WatchGuard EDR initially prevented from running. These programs were classified as a threat (malware, PUP, or exploit) or unknown files in the process of classification.

Screen shot of the Programs Allowed by the Administrator tile

Click the tile to display specific information in a list.

Screen shot of the Programs Allowed by the Administrator detail page

Click History to review all events related to threats and unknown files in the process of classification that the administrator allowed to run.

Programs Blocked By the Administrator

The Programs Blocked by the Administrator tile shows the number of programs blocked by the administrator on the computers on the network.

Screen shot of the Programs Blocked by the Administrator tile

Click the tile to display specific information in a list.

Screen shot of the Programs Blocked by the Administrator detail page

Classification of All Programs Run and Scanned

This tile shows the processes and programs run in your organization for the selected time period and their classification (for example, trusted programs, or malware).

The data in this tile corresponds to the entire IT network, not only to those computers that the administrator has permissions for.

Programs under classification are shown in the tile after they are classified:

Screen shot of the Classification of all Programs Run and Scan tile

Program Classification

  • Trusted Programs — Programs run in the selected period that WatchGuard EDR classified as trusted.
  • Malware — Programs that tried to run in the selected period, and WatchGuard EDR classified as malware, zero-day threats, or targeted attacks.
  • Exploits — Exploit attacks that compromised or tried to compromise trusted programs on computers.
  • PUPs (Potentially Unwanted Programs) — Programs that attempted to run in the selected period, and WatchGuard EDR classified as PUPs.

Malware Activity, Pup Activity, and Exploit Activity

These tiles show incidents detected in the processes run by the workstations and servers on the network, as well as their file systems. Incidents are reported by real-time scans as well as on-demand scan tasks.

WatchGuard EDR generates an incident in the Malware and PUP tiles for each computer or threat pair found on the network. If an incident occurs multiple times in five minutes, only the first incident is registered. The same incident can be registered a maximum of two times every 24 hours.

Screen shot of the Malware Activity and PUP Activity tiles

The Exploit Activity tile shows the number of vulnerability exploit attacks against the Windows computers on the network. WatchGuard EDR reports an incident in the Exploit activity panel for each computer or different exploit attack pair found on the network. If an attack is repeated several times, a maximum of 10 incidents are reported every 24 hours for each computer-exploit pair found.

Screen shot of the Exploit Activity tile

Currently Blocked Programs Being Classified

The Currently Blocked Programs Being Classified tile shows the number of programs that are currently blocked by WatchGuard EDR.

Screen shot of the Currently Blocked Programs Being Classified tile

Click the tile to see a list of files that WatchGuard EDR determined to be risky before classification. To remove a program from the list, from the options menu for a computer, select Delete from list.

Screen shot of the Currently Blocked Programs Being Classified details

See Also

My Lists

Unmanaged Computers Discovered List