Security Check Explorer¶
- Version: 1.0.7-7-g251eead
- Release Date: 2023-04-06 11:17:57
- Supported OS: windows/amd64, windows/386, linux/arm, linux/arm64, linux/386, linux/amd64
Introduction¶
Guance enables you to monitor, query, and correlate all security check events in real time through Security Check. It helps you detect vulnerabilities, anomalies, and risks promptly while improving the quality of inspections, issue analysis, and incident handling.
Overview¶
In Security Check > Overview, Guance provides a default security check monitoring view. You can filter by host, security check severity, and security check category to view the overview of security check events occurring on different hosts, including the count of events at each severity level, visual chart analysis, and top lists of events by category and rule.
You can also click the Jump button to navigate to the corresponding built-in view page linked from the overview, then clone and modify that view. For more details, see Built-in Views.
Data Query and Analysis¶
In Security Check > Explorer, you can query security check events by selecting a time range, searching keywords, and applying filters.
Security Check Event Statistics¶
Guance counts the number of security check events in different states at each time point based on the selected time range. You can view the event count over time using a stacked bar chart, choose different time intervals for the statistics, and export the data to a dashboard, note, or copy it to the clipboard.
Time Widget¶
The Guance Explorer displays data from the last 15 minutes by default. Use the Time Widget in the upper-right corner to select the time range for data display.
Search and Filter¶
The search bar in the Explorer supports keyword search, wildcard search, related search, JSON search, and more. You can filter values by tags/attributes using positive filter, negative filter, fuzzy match, negative fuzzy match, exists, and does not exist. For more details, see Search and Filter in the Explorer.
Quick Filter¶
In the Quick Filter section of the Explorer, you can edit the Quick Filter to add new filter fields. After adding, you can select field values to apply quick filtering. For more details, see Quick Filter.
Custom Display Columns¶
When viewing the list, you can use Display Columns to customize, add, edit, delete, and reorder columns. Hover over a display column in the Explorer and click the Settings button to sort columns in ascending or descending order, move columns left or right, add columns to the left or right, replace columns, add columns to Quick Filter, add columns to grouping, and remove columns.
Data Export¶
The security check event list supports exporting the current list data as a CSV file to a local device, or exporting to a Scenarios dashboard or note, via the settings button above the list.
Save Snapshot¶
Guance supports creating quickly accessible data copies. With the snapshot feature, you can instantly reproduce a copied data snapshot, restoring data to a specific point in time with a specific data display logic.
You can perform search and filter on the displayed data, select a time range, add display columns, etc., then click the Snapshot icon in the upper-left corner of the Explorer and click Save Snapshot to save the current data displayed in the Explorer. You can also share snapshots, copy snapshot links, and delete snapshots in the history. For more details, see Snapshot.
Security Check Event Details¶
When you click the tag host or an attribute field, you can use Filter by field value, Inverse filter by field value, Add to display columns, and Copy for quick filtering and viewing. You can also click View related logs, View related containers, View related processes, and View related traces to directly navigate to the host-related data Explorer for correlation analysis.
- Filter by field value: Adds the field to the Explorer to view all data related to it.
- Inverse filter by field value: Adds the field to the Explorer to view all data except that field.
- Add to display columns: Adds the field to the Explorer list for viewing.
- Copy: Copies the field to the clipboard.
Recommendations¶
Click the security check event you want to view. In the expanded detail panel, you can see recommendations for handling this event, including the theoretical basis, risk items, audit methods, and remediation measures.
Related Security Checks¶
In the Related Security Checks section of the event details page, you can match related events by selecting tags (including host, category, and rule). You can also search for related events based on the event name and content.
Related Host¶
In the security check details page, click Host below to view the metrics view and attribute view of the related host (associated field: host).
Note: To view the related host in process details, the field host must match; otherwise, the related host page will not be displayed in process details.
- Metrics View: Displays the host performance metrics from 30 minutes before the event ends to 30 minutes after the log ends, including CPU, memory, and other performance indicators of the related host.
- Attribute View: Helps you reconstruct the real state of the host object when the security check data was generated. It displays the latest object data within 10 minutes before the event ends, including basic host information and integration status. If cloud host collection is enabled, cloud provider information is also shown.
Note: Guance retains host object historical data for the last 48 hours by default. If no host historical data matching the current log time is found, you will not be able to view the attribute view of the related host.








