Skip to main content

Data Security Dashboard

The Data security dashboard is the first place to look after a scan. It pulls every File Server and SharePoint Online source into one view: the number of repositories and objects scanned, the sensitive data findings, and the permissions collected, with a table at the bottom that lists each share and site. A second tab shows access events from Netwrix Activity Monitor.

Open it from Dashboards > Data security. Users with the Admin or Viewer role can see it. Dashboards and reports explains the Refresh button, how to drill into a chart, and how fresh the numbers are.

Data security dashboard, Scan Overview tab, full page

Data Prerequisites

An Access scan on your File Server and SharePoint Online sources fills the Scan Overview tab. Until a Sensitive data scan has run on those sources as well, Sensitive Data Findings shows 0, Sensitive Data by Source stays empty, and the Sensitive Files and Sensitive Findings columns of Data Source Inventory have nothing to report. The Activity tab holds no scan data at all: it shows events from Netwrix Activity Monitor and stays empty until that connection is in place. Scan types covers the scans; Netwrix Activity Monitor covers the feed.

Tabs and Filters

The dashboard has two tabs, Scan Overview and Activity. Each tab has its own filters, shown above its cards, and every filter applies as soon as you change it.

FilterTabWhat it does
Data SourceScan OverviewLimits every card except SharePoint Sites by Type to File Servers, SharePoint Online, or both
Start DateActivityEarliest event time to include
End DateActivityLatest event time to include
Event TypeActivityOne or more event types, drawn from the events Access Analyzer has received
Activity SourceActivityFile Servers, SharePoint Online, or Microsoft Copilot
UserActivityOne or more users who performed events
Event StatusActivitySuccess or Failed

All filters are optional and start empty, which means no restriction.

Scan Overview Tab

The table lists the cards in the order they appear, top to bottom and left to right.

CardWhat it showsHow to read it
Total Data RepositoriesThe number of file shares plus SharePoint Online site collections your scans have coveredThe breadth of coverage; if you expect 40 shares and see 12, you haven't scanned some sources yet
Total Objects ScannedThe number of objects collected from file servers and SharePoint OnlineRises with each newly scanned source
Sensitive Data FindingsThe total number of pattern matches across both source typesZero until a Sensitive data scan has run; a single file can contribute several matches
Permissions AnalyzedThe number of permission entries collectedA rough measure of how much data the permission reports draw on
Objects by Data SourceA bar chart comparing object counts for File Servers and SharePoint OnlineShows where the bulk of your data sits
Sensitive Data by SourceA pie chart splitting the findings between File Servers and SharePoint OnlineShows which platform carries more sensitive content
File Server Objects by HostA bar chart of object counts per file serverPicks out the largest servers; each bar is one host
SharePoint Sites by TypeA pie chart of SharePoint Online sites by site typeThe Data Source filter doesn't affect it
Data Source InventoryOne row per share or SharePoint Online site, with columns Source Type, Location, Total Objects, Files, Folders, Sensitive Files, and Sensitive FindingsSorts by total objects, largest first; shows up to 20,000 rows; shares appear as \\host\share paths

Activity Tab

Data security dashboard, Activity tab, with date, event type, source, user, and status filters

Every card on this tab responds to the six Activity filters. Start Date and End Date bound the time range; the other four narrow the events further.

CardWhat it showsHow to read it
Total EventsThe number of events in the selected rangeYour baseline for the period
Failed EventsThe number of events with status FailedA spike is worth investigating: check which users and resources the failures cluster on
Active UsersThe number of distinct users with at least one eventCompare with Total Events to see whether activity is spread out or concentrated
Data Sources with ActivityHow many of the three activity sources reported eventsShows whether every feed you expect is reporting events
Events by TypeA bar chart of event counts per event typeOne bar per event type; pick a single type in Event Type to isolate it across the other cards
Activity Over TimeA line chart of event counts over the rangeLook for bursts outside working hours
Events by Data SourceA pie chart of events per activity sourceShows which platform generates most of the traffic
Top Users by ActivityA horizontal bar chart of users ranked by event countThe busiest accounts, which are worth checking against their roles
Activity DetailThe most recent 500 events, with columns Time, Source, Event Type, User, Resource, Location, and StatusNarrow the filters until fewer than 500 events match, so the table shows all of them

For a closer look at file server activity, open the Activity Investigation report from Data reports. It filters by user, path, and event type. Group By sets the timeline's unit, day by default.