To access Security Insights, log into LiveNX as an admin user and click the Security Insights button in the top menu bar.
Once the data loads, your new Security Insights dashboard will appear. See below for an overview of the dashboard components:
Top security findings
Highlights the most frequent detections across the monitored network. These insights help pinpoint misconfigurations or legacy systems that may weaken overall security posture.
Top applications
Displays the applications most often associated with security findings. Filtering by any parameter refines the dashboard (charts and table) to show findings, IPs, and ports relevant only to that query.
MITRE ATT&CK categories
Findings are automatically mapped to MITRE ATT&CK categories and this mapping assists in understanding the broader intent behind each alert.
Source and destination analysis
- Top Source IPs identify where network threats originate.
- Top Destination IPs reveal systems being targeted or affected.
- Top Source/Destination Ports show which protocols are in use (e.g., 443,
80, 3389).
Together, these visuals help trace and validate network behavior for potential compromises.
Severity and data sources
- Severity Overview: identifies the findings severity.
- Sources: Findings are derived primarily from LiveWire Flow (packet-based traffic analysis).
You can apply different filters or time ranges, i.e. by application, IP, category, source, domain, etc.
Findings over time
The time-series graph displays when detections occurred, helping identify trends or unusual spikes. In the following example, most findings were steady, with a single noticeable spike around October 25th.
Detailed findings table
Each individual detection is listed in the detail view. In the following example, multiple “TLS Weak Cipher Suite” alerts are observed between internal IPs (10.4.2.x → 10.4.58.x), and captured by LiveWire Flow.