Dashboard

MetaDefender Core provides a Web-based user interface (default port is 8008) that gives a general overview of MetaDefender Core status and allows you to configure its options.

Security page

The Security page shows information on

Processing Summary

Displays a summary for the selected instance and time range: total files scanned, allowed, blocked, and failed.


Threats Detected

Displays the top threat verdicts detected and top file-blocking verdicts within the selected time range.


Data Loss Prevented


Number of Sanitized


Security Trend

Displays Security Trend charts — threats detected, DLP hits, and sanitized files over time — for the selected range, grouped by hourly, daily, weekly, or monthly time buckets.


Top 5 File Types with Threats Detected


Verdicts Blocked Detected


Top 5 File Types by Verdict


CVE Volume Trend

Displays CVE detections over time, broken down by severity (Critical, Important, Moderate, Low, or Unknown) for the selected time range and bucket size.


Most Active CVEs

Displays the most frequently detected CVEs for the selected time range, along with their severity and number of detections


Top 10 Countries Detected


Top 10 Vendors Detected


System page

The System page page shows information on

File Submission

Displays the number of submitted and blocked files over time for the selected time range, processing rule, and bucket size (hourly, daily, or monthly), counted either per submission or per object



File Processing Time

Displays the File Processing Time widget, showing how long each engine spent processing files over time (in milliseconds) for the selected time range and bucket size (hourly, daily, or monthly), viewable as an average or total


Reuse Processing Result


Total Objects Scanned


Usage page

The usage page is to provide the current system resource status (CPU, memory and disk) and processing performance (scan queue) of MetaDefender Core server.



Quarantine

The Quarantine page shows all scanned files which are copied to the quarantine. Each of them can be pinned to avoid removal on cleaning up. Also comments can be written to each quarantined file. Quarantine log can be searched for comment, file name and source of the scan request.

Update history

The Update history shows information on every update package related event.

On the Update history page you can also search for engine name, package type or message content. Also you can filter the list for severity.

Configuration history

The Configuration history shows information on user activity events regarding workflow rule changes, setting changes, engine setting changes, licensing.

You can search for text on the Configuration history page and filter the list for datetime.