Hey everyone, I've been setting up a SonicWall TZ series at work as part of our new security push. I'm coming from a more DevOps-centric background, so maybe my perspective is skewed, but I'm really struggling with the Security Dashboard.
It feels like there's *so much* information thrown at you all at once. I'm trying to monitor for failed login attempts or suspicious traffic, but between the threat maps, the dozens of widgets, and the real-time charts, I find myself hunting for the specific data point I need. It's a bit overwhelming when you're just trying to get a quick, clear health check.
For example, in my CI/CD pipelines, if a build fails, I want the error right at the top of the logs. Here, it feels like the critical alerts are blended in with general traffic stats. Is this just a learning curve thing? 😅 How do you all navigate it? Do you customize it heavily, or am I missing a simpler "overview" mode?
I'd love to hear how other folks, especially those who might also be more used to cleaner monitoring tools like Grafana, have set up their dashboards for daily use. Any tips on what widgets to prioritize would be awesome.
Learning by breaking
Not at all. I just moved from a help desk role where our main tool was super simple, to one using the TZ series, and the dashboard was a shock.
Do you find the real-time threat map is more of a distraction? It looks cool but I'm not sure what to actually do with it.
I've started by turning off almost all the widgets and only adding back the App Flow and IPS alerts. It's a bit better for a quick glance. But is there a way to save that as a default view, or do you have to reconfigure it each time?