Kaspersky Anti Targeted Attack Platform
[Topic 175014]

About widgets and layouts

You can use widgets to monitor program operation.

A layout is the appearance of the workspace of the program web interface window in the Dashboard section. You can add, delete, and move widgets in the layout.

The following widgets are available in the program:

  • Processed. Displays the processing state for traffic coming from Sensor component and Kaspersky Endpoint Agent program to the server with the Central Node component.
  • Queues. Displays information on the number and volume of objects waiting to be scanned by the program modules and components.
  • Sandbox processing time. Displays the average time taken to receive the scan results after objects were scanned by the Sandbox component.

If you are using the

and , the section displays information about the tenant and server that you chose.

See also

Monitoring program operation

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 196215]

Selecting a tenant and a server to manage in the Dashboard section

If you are using the distributed solution and multitenancy mode, before using the Dashboard section, you must select the tenant and server whose data you want to view.

To select a tenant and server for which you want to display data in the Dashboard section:

  1. In the upper right part of the program web interface window, click the arrow next to the server name.
  2. In the drop-down list, select the tenant and server from the list.

Data for the selected server is displayed. If you want to select a different tenant and server, repeat the steps to select a tenant and server.

Page top
[Topic 183135]

Adding a widget to the current layout

To add a widget to the current layout:

  1. Select the Dashboard section in the program web interface window.
  2. In the upper part of the window, click the Apt_icon_dashboard_menu button.
  3. In the drop-down list, select Customize.
  4. Click Widgets.
  5. In the Manage widgets window that opens:
    • If you want to add the Queues widget, turn on the toggle switch next to the name of this widget.
    • If you want to add the Sandbox processing time widget, turn on the toggle switch next to the name of this widget.
    • If you want to add the Processed widget, click Apt_icon_tasks_add_filter next to the name of this widget.

The selected widget is added to the current layout.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 196216]

Moving a widget in the current layout

To move a widget in the current layout:

  1. Select the Dashboard section in the program web interface window.
  2. In the upper part of the window, click the Apt_icon_dashboard_menu button.
  3. In the drop-down list, select Customize.
  4. Select the widget that you want to move within the layout.
  5. Left-click and hold the upper part of the widget to drag and drop the widget to a different place in the layout.
  6. Click Save.

The current layout is saved.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 175306]

Removing a widget from the current layout

To remove a widget from the current layout:

  1. Select the Dashboard section in the program web interface window.
  2. In the upper part of the window, click the Apt_icon_dashboard_menu button.
  3. In the drop-down list, select Customize.
  4. Click the Apt_icon_dashboard_customize_close icon in the upper right corner of the widget that you want to remove from the layout.

    The widget is removed from the workspace of the program web interface window.

  5. Click Save.

The widget is removed from the current layout.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 175307]

Saving a layout to PDF

To save a layout to PDF:

  1. Select the Dashboard section in the program web interface window.
  2. In the upper part of the window, click the Apt_icon_dashboard_menu button.
  3. In the drop-down list, select Save as PDF.

    This opens the Saving as PDF window.

  4. In the lower part of the window, in the Layout drop-down list, select the page orientation.
  5. Click Download.

    The layout in PDF format is saved to the hard drive of your computer in the downloads folder of the browser.

  6. Click Close.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 175868]

Configuring the data display period in widgets

You can configure the display of data in widgets for the following periods:

  • Day
  • Week
  • Month

To configure the display of data in widgets for a day (from 00:00 a.m. to 11:59 p.m.):

  1. Select the Dashboard section in the program web interface window.
  2. In the upper-right corner of the program web interface window, in the drop-down list of data display periods, select Day.
  3. In the calendar to the right of the Day period name, select the date for which you want to display data in the widget.

All widgets on the Dashboard page display data for the period you selected.

To configure the display of data on widgets for a week (Monday through Sunday):

  1. Select the Dashboard section in the program web interface window.
  2. In the upper-right corner of the program web interface window, in the drop-down list of data display periods, select Week.
  3. In the calendar to the right of the Week period name, select the week for which you want to display data in the widget.

All widgets on the Dashboard page display data for the period you selected.

To display data display in widgets for a month (calendar month):

  1. Select the Dashboard section in the program web interface window.
  2. In the upper-right corner of the program web interface window, in the drop-down list of data display periods, select Month.
  3. In the calendar to the right of the Month period name, select the month for which you want to display data in the widget.

All widgets on the Dashboard page display data for the period you selected.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 175309]

Monitoring the receipt and processing of incoming data

In the Processed widget, you can assess the processing status of data coming from the Sensor component and Kaspersky Endpoint Agent component to the server with the Central Node component, and track data processing errors.

To select the component (Sensor or Kaspersky Endpoint Agent) for which you want to assess incoming data, use the drop-down list to the right of the Processed widget name.

You can select the type of data display in the drop-down list to the right of the component name (Sensor or Kaspersky Endpoint Agent):

  • Current load—The last 5 minutes.
  • Selected period. In this case, you can also configure the period of data display on widgets.

The left part of each widget displays the legend for colors used in the widget itself.

If the Current load data display type is selected, the average data processing rate over the past 5 minutes is displayed to the right of the key.

Example:

The Processed widget has (SPAN) or (ICAP) Sensor type and Current load data display type selected and displays the data processing rate for SPAN and ICAP traffic coming from the Sensor component to the server with the Central Node component over a specific time period.

The following data is displayed:

  • Traffic—Rate of incoming traffic to the server with the Central Node component, indicated in green (Mbps).
  • Files—Rate of file processing indicated in gray (objects per second).
  • URLs—Rate of URL processing indicated in blue (objects per second).
  • Unprocessed—Number of unprocessed objects indicated by vertical red lines.

    When you move the mouse cursor over a widget, you see a pop-up window that displays the data processing rate for a specific time period.

    The Processed widget has (SMTP) Sensor type and Current load data display type selected and displays the data processing rate for mail traffic coming from the mail sensor to the server with the Central Node component over a specific time period.

    The following data is displayed:

  • Traffic—Rate of incoming traffic to the server with the Sensor component, indicated in green (messages per second).
  • Files—Rate of file processing indicated in gray (objects per second).
  • URLs—Rate of URL processing indicated in blue (objects per second).
  • Unprocessed—Number of unprocessed objects indicated by vertical red lines.

    When you move the mouse cursor over a widget, you see a pop-up window that displays the data processing rate for a specific time period.

    The Processed widget has (LOAD) Endpoint Agents Sensor type and Current load data display type selected and displays the processing rate for events coming from Endpoint Agent components to the server with the Central Node component over a specific time period (events per second).

    When you move the mouse cursor over a widget, you see a pop-up window that displays the data processing rate for a specific time period.

If the Selected period data display type is selected, to the right of the key you will see the average rate of incoming traffic to the server with the Central Node component and the number of objects processed during the selected period.

Example:

The Processed widget with an (SPAN) or (ICAP) Sensor, Selected period data display type, and Month data display period selected, displaying the rate of SPAN and ICAP traffic coming to the server with the Central Node component, as well as the number of files and URLs extracted from mail traffic during the selected month.

The following data is displayed:

  • Average traffic—Rate of incoming traffic to the server with the Central Node component, indicated in green (objects per second).
  • Files—Number of extracted files indicated in gray.
  • URLs—Number of extracted URLs indicated in blue.
  • Unprocessed—Number of unprocessed objects indicated by vertical red lines.

    When you move the mouse cursor over a widget, you see a pop-up window that displays the rate of incoming traffic to the server with the Central Node component and the number of objects processed during a specific time period.

    The Processed widget with an (SMTP) Sensor, Selected period data display type, and Month data display period selected, displaying the data processing rate of mail traffic coming to the server with the Central Node component, as well as the number of files and URLs extracted from mail traffic during the selected month.

    The following data is displayed:

  • Average traffic—Rate of incoming traffic to the server with the Central Node component, indicated in green (objects per second).
  • Files—Number of extracted files indicated in gray.
  • URLs—Number of extracted URLs indicated in blue.
  • Unprocessed—Number of unprocessed objects indicated by vertical red lines.

    When you move the mouse cursor over a widget, you see a pop-up window that displays the rate of incoming traffic to the server with the Central Node component and the number of objects processed during a specific time period.

    The Processed widget with (LOAD) Endpoint Agents Sensor type, Selected period data display type, and Month data display period selected, displaying the number of events coming from hosts with Kaspersky Endpoint Agent program to the server with the Central Node component during the selected month.

    When you move the mouse cursor over a widget, you see a pop-up window that displays the number of events for a specific time period.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 196218]

Monitoring the queues for data processing by program modules and components

You can use the Queues widget to assess the status of data processing by the

and program modules and the component and monitor the amount of unprocessed data.

Data transfer in the queue is measured in messages.

You can select the type of data display in the drop-down list to the right of the Queues widget name:

  • Current load—The last 5 minutes.
  • Selected period. In this case, you can also configure the period of data display on widgets.

The left part of the widget displays the legend for colors used in the widget.

The Queues widget displays the following data:

  • Number of messages and Data volume processed by program modules and components:
    • YARA—blue.
    • Sandbox—violet.
    • AM Engine—green.
  • Unprocessed—amount of unprocessed data indicated by vertical red lines.

When you hover the mouse cursor over a widget, you see a pop-up window that displays the status of data processing by the YARA and AM Engine program modules and the Sandbox component, as well as the amount of unprocessed data during a specific time period.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the processing of data by the Sandbox component

Viewing the working condition of modules and components of the program

Page top
[Topic 196219]

Monitoring the processing of data by the Sandbox component

The Sandbox processing time widget displays the average time elapsed from the moment data is sent to one or multiple Sandbox component servers (including the time spent in the queue before getting sent) to the moment when the Sandbox processing results are displayed in the web interface of Kaspersky Anti Targeted Attack Platform for the selected period.

Example:

If Month is configured as the period of data display in widgets, the Sandbox processing time widget displays orange-colored bars for each day of the month.

When you move the mouse cursor over each column, you will see a pop-up window that displays the average time that elapses from the moment data is sent to one or several servers with the Sandbox component until the results from data processing by the Sandbox component are displayed in the web interface of Kaspersky Anti Targeted Attack Platform during the selected day.

You can increase the rate at which data is processed by the Sandbox component and the throughput of the Sandbox component by increasing the number of servers with the Sandbox component and by distributing the data to be processed among those servers.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Viewing the working condition of modules and components of the program

Page top
[Topic 183130]

Viewing the working condition of modules and components of the program

If modules or components of the program encounter errors that the administrator is advised to look at, a yellow warning box is displayed in the upper part of the Dashboard section of the program web interface.

Users with the Local administrator, Administrator, or Security auditor roles can gain access to information about the working condition of the Central Node, PCN, or SCN server that the user is currently managing.

Users with the Senior security officer, Security officer, or Security auditor roles can gain access to the following information about the working condition:

  • If you are using a standalone Central Node server, the user can access information about the working condition of the Central Node server which the user is currently managing.
  • If you are using the distributed solution and multitenancy mode, and the user is managing an SCN server, the user can gain access to information about the working condition of that SCN server for tenants to whose data the user has access.
  • If you are using the distributed solution and multitenancy mode, and the user is managing the PCN server, the user can gain access to information about the working condition of the PCN server and all SCN servers connected to that server, for tenants to whose data the user has access.

For details about the working condition of program modules and components,

click View details to open the System health window.

In the System health window, one of the following icons is displayed depending on the working condition of the program modules and components:

  • kata_dashboard_icon_ok if the modules and components of the program are working normally.
  • An icon with the number of problems (for example, kata_dashboard_icon_error_yellow) if problems are found that the administrator is recommended to pay attention to. In this case, detailed problem information is displayed in the right part of the System health window.

The System health window contains the following sections:

  • Component health contains information on the operational status of program modules and components, Quarantine, and database update on all servers where the program is operating.

    Example:

    If the databases of one or more program components have not been updated in 24 hours, the kata_dashboard_icon_exclamation_yellow icon is displayed next to the name of the server on which the program modules and components are installed.

    To resolve the problem, make sure that update servers are available. If you are using a proxy server to connect to update servers, make sure the proxy server has no errors pertaining to the connection to Kaspersky Anti Targeted Attack Platform servers.

  • Processed—Status of receiving and processing incoming data. The status is generated based on the following criteria:
    • State of receiving data from servers with the Sensor component, from the server or virtual machine with the mail sensor, from Kaspersky Endpoint Agent hosts.
    • Information about exceeding the maximum allowed time that objects wait in the queue to be scanned by program modules and components.
  • Connection with servers—Status of the connection between the PCN server and connected SCN servers (displayed if you are using the distributed solution and multitenancy mode).

If there are problems detected in the performance of program modules or components and you cannot resolve those problems on your own, you are advised to contact Kaspersky Technical Support.

See also

Monitoring program operation

About widgets and layouts

Selecting a tenant and a server to manage in the Dashboard section

Adding a widget to the current layout

Moving a widget in the current layout

Removing a widget from the current layout

Saving a layout to PDF

Configuring the data display period in widgets

Monitoring the receipt and processing of incoming data

Monitoring the queues for data processing by program modules and components

Monitoring the processing of data by the Sandbox component

Page top
[Topic 196328]