Start an investigation based on a dashboard chart

Security dashboard & security investigation tool
Supported editions for this feature: Frontline Standard; Enterprise Standard and Enterprise Plus; Education Standard and Education Plus; Enterprise Essentials Plus; Cloud Identity Premium. Compare your edition

You can start an investigation by clicking a link in some security dashboard reports. The search results are then pre-populated in the security investigation tool. 

This feature is available from the following charts on the dashboard:

  • File exposure—What does external file sharing look like for the domain?
  • Compromised device events—What compromised device events have been detected?
  • Suspicious device activities—What suspicious device activities have been detected?
  • Failed device password attempts—How many times were there failed password attempts on devices?

Start an investigation from the security dashboard

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. In the Admin console, go to Menu and then Securityand thenSecurity centerand thenDashboard.
  3. From one of the above charts, click VIEW REPORT
  4. Apply filters to the report, such as the date range or domain.
  5. Start an investigation by hovering on the investigation icon  in the report, and then clicking New Investigation. You can start an investigation based on the entire table in the report, or based on a single row in the table.
  6. Click SEARCH.

Was this helpful?

How can we improve it?
Search
Clear search
Close search
Google apps
Main menu
5923486072042800621
true
Search Help Center
true
true
true
true
true
73010
false
false