Curated dashboard queries: UDM and datatable
This document is for Security Operations Center (SOC) managers and analysts who want to monitor threat landscapes and system health using curated dashboards— predefined dashboards designed for visibility across various security use cases. This document provides a collection of curated dashboards and their underlying queries for the UDM and datatablesource type.
You can use these queries in the query editor or as a baseline for custom widgets. For information on how to create and manage dashboards, see Manage dashboards .
| Dashboard name | Description | Chart name | Query |
|---|---|---|---|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Vulnerabilities by Severity |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Permission Changes Over Time by Log Type |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
MFA Events Over Time by Action |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Login Events Over Time by Action |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Top 10 ePHI Hosts by DLP Violations |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
EDR Alerts Over Time by Severity |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Backup Events Over Time by Action |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Password Changes Over Time by Action |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Recent Backup Events (Last 24 Hours) |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Recent EDR Alerts (Last 24 Hours) |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Recent User Account Creations (Last 24 Hours) |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Weak Encrypted Communication Over Time by Log Type |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Recent User Change Password (Last 24 Hours) |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Top 10 SaaS Applications |
|
|
HIPAA Dashboard
|
Monitors HIPAA compliance and security metrics in real-time. Provides visibility into PHI access and potential risks to ensure data confidentiality and integrity. Note: Requires the ePHI_assets.Hostname
data table to be created before charts populate. |
Top 10 Key Operations |
|
Need more help? Get answers from Community members and Google SecOps professionals.

