Curated dashboard queries: Ingestion metrics
This document is for Security Operations Center (SOC) managers and analysts who want to monitor threat landscapes and system health using curated dashboards— predefined dashboards designed for visibility across various security use cases.
You can use these queries in the query editor or as a baseline for custom widgets. For information on how to create and manage dashboards, see Manage dashboards.
| Dashboard name | Description | Chart name | Query example |
|---|---|---|---|
| ISO 27001 – Technological Controls |
Provides visibility into technological controls and encryption standards to support compliance and data-driven remediation. Note: Filters are required to refine the data. |
Last Heartbeat Time by Log Type |
|
| CIS Controls Compliance Overview | Provides visibility into CIS critical security controls to strengthen governance. It tracks key metrics like asset accuracy, vulnerability progress, and backup reliability to ensure operational preparedness. | Ingestion Throughput Over Time |
|
| CIS Controls Compliance Overview | Provides visibility into CIS critical security controls to strengthen governance. It tracks key metrics like asset accuracy, vulnerability progress, and backup reliability to ensure operational preparedness. | Ingested Events by Log Type |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Count (Last 7 Days) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput Weekly |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Events by Status |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput Weekly |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Count (Last 7 Days) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Recently Ingested Logs |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Burst Rejection Graph |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Recently Ingested Logs |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput (Last 6 Months) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingested Events Count |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Size (Last 3 Months) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Burst Limit Graph - Quota Limit |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Count (Last 3 Months) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Log Type Distribution by Throughput |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Burst Limit Graph - Quota Limit |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Count (Last 24 Hours) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Log Type Distribution by Throughput |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Size (Last 7 Days) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Count (Last 3 Months) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingested Events Count |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput (All-Time) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Burst Rejection Graph |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Size (Last 7 Days) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput Hourly |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput (Last 6 Months) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion Error Count |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Events by Status |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Log Type Distribution by Events Count |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion Error Count |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Burst Limit Graph - Ingestion Rate |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput (All-Time) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Log Type Distribution by Events Count |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Burst Limit Graph - Ingestion Rate |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Daily Log Information |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Events by Log Type |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Size (Last 3 Months) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Size (Last 24 Hours) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Size (Last 24 Hours) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Event Count (Last 24 Hours) |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Throughput |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Throughput Hourly |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Daily Log Information |
|
| Data Ingestion and Health | Monitors data flow, error counts, and log distributions. Tracks ingestion throughput and activity over time to identify trends and streamline troubleshooting. | Ingestion - Events by Log Type |
|
| FEDRAMP Continuous Monitoring | Provides Security and Compliance Teams a real-time view of system posture. Tracks vulnerabilities and control effectiveness against FedRAMP standards to prioritize remediation and maintain continuous compliance. | Last Heartbeat Time by Log Type |
|
| HIPAA Dashboard |
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity.
Note: Requires the ePHI_assets.Hostname data table to be created before charts populate.
|
Last Heartbeat Time by Log Type |
|
| Main | The Main dashboard offers a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Ingested Events |
|
| Main | The Main dashboard offers a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Ingested Events |
|
| Main | The Main dashboard offers a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Events Over Time |
|
| Main | The Main dashboard offers a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Throughput |
|
| Main | The Main dashboard offers a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Throughput |
|
| Main | The Main dashboard offers a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Events Over Time |
|
| Mandiant Hunting | Provides visibility into proactive Mandiant threat hunting. Tracks ongoing and completed activities while highlighting security trends discovered during the hunting process. | Total Events Ingested |
|
| NIST 800-53 - Audit and Accountability | Monitors log management and audit activities aligned with NIST 800-53 standards. Lets SOC teams manage audit logs to ensure security and continuous compliance. | Log Ingestion Latency |
|
| NIST 800-53 - Audit and Accountability | Monitors log management and audit activities aligned with NIST 800-53 standards. Empowers SOC teams to manage audit logs effectively for continuous security and compliance. | Parsing Rate by Log Type |
|
| NIST 800-53 - Audit and Accountability | Monitors log management and audit activities aligned with NIST 800-53 standards. Empowers SOC teams to manage audit logs effectively for continuous security and compliance. | Log Ingestion Volume by Log Type |
|
| NIST 800-53 - Audit and Accountability | Monitors log management and audit activities aligned with NIST 800-53 standards. Empowers SOC teams to manage audit logs effectively for continuous security and compliance. | Last Heartbeat Time by Log Type |
|
| PCI - Monitoring and Testing |
Monitors and tracks access to cardholder data within the PCI environment. Uses the `PCI_Assets` and `Default_Users` reference lists to scope data.
Note: Required reference lists must be created before charts populate. |
SIEM Log Source Heartbeat |
|
| SecOps Audit & Activity Monitoring | Monitors security posture, events, and user activities within Chronicle Google APIs. Tracks blocked actions to provide visibility into potential threats and system health. | Ingestion Health Status |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Ingestion Throughput (GB) by Log Type |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Monthly Year-To-Date Log Ingestion |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Ingestion Throughput (GB) |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Log Ingestion Latency |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Ingested Logs by Log Type |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Top 10 Ingested Logs by Log Type |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Parsing Success Rate by Log Type |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Year-to-Date Daily Log Ingestion |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Year-To-Date Log Ingestion |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Forwarder Container Usage |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Active Log Source Trend |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Recent Pipeline Latency Count |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Log Ingestion Volume by Log Type |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Last Heartbeat Time by Log Type |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Recent Component Status |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Total Year-To-Date Log Ingestion |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Ingested Logs by Event Type |
|
| SecOps Log Monitoring | Monitors log ingestion latency and component status to optimize performance. Helps reduce data loss and ensures high-fidelity security monitoring across the environment. | Ingested Logs by Component |
|
| Security Management Overview | Provides a centralized view of security operations by tracking case activity, incident trends, and response performance. Helps teams monitor progress and identify risks to improve overall security effectiveness. |
|
|
| User Sign In Overview | Monitors authentication activities to identify and track sign-in events. Analyzes geographical activity, associated hosts, and sign-in trends to detect risky users and unusual login behaviors for proactive threat detection. | Ingestion by Log Source (24 Hours) |
|
Need more help? Get answers from Community members and Google SecOps professionals.