Curated dashboard queries: IOC matches
This document is for Security Operations Center (SOC) managers and analysts who want to monitor threat landscapes and system health using curated dashboards— predefined dashboards designed for visibility across various security use cases. This document provides a collection of curated dashboards and their underlying queries for the SOAR casessource type.
You can use these queries in the query editor or as a baseline for custom widgets. For information on how to create and manage dashboards, see Manage dashboards .
| Dashboard name | Description | Chart name | Query example |
|---|---|---|---|
|
CIS Controls Compliance Overview
|
Monitors adherence to CIS Critical Security Controls, including asset accuracy, vulnerability remediation, and access enforcement. | Top 10 Asset communicating with IOCs |
|
|
Main
|
Provides a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Global Threat Map - IOC IP Matches |
|
|
Main
|
Provides a summary of data ingestion health and detected IoCs, and provides a global perspective on potential threats. | Global Threat Map - IOC IP Matches |
|
|
Network Traffic Overview
|
Network Traffic Dashboard offers real-time Real-time monitoring of cloud and on-prem traffic by IP, protocol, and region. | Top 10 Asset communicating with IOCs |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | IOCs by Severity |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | IOCs by Category |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | Suspicious IP Accesses |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | Top 10 Domain Indicators |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | New IOCs Ingestion by type |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | Hosts Communicating with IOCs |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | Top 10 IP Indicators |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | IOCs Count Over Time |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | Latest IOCs |
|
|
Threat Intelligence Overview
|
Provides real-time insights into IOCs and risk scores, enabling faster detection of emerging infrastructure threats. | IOCs Geolocation Overview |
|
Need more help? Get answers from Community members and Google SecOps professionals.

