Summary and evidence
The Summary tab of External access answers the auditor’s questions for a period: how many direct logins there were, whether every finding was reviewed, how standing entries were reviewed week by week, and whether every server was covered on every day. Export evidence downloads the same answer as files.
Pick a period
Choose a Period: This week, Last week, This month, Last month, Last 90 days, or Custom with a start and an end date.
- A period is at most 366 days.
- Days follow the workspace’s time zone, and both the start and the end day are included.
- The start can’t be after today. A period that runs past today is counted up to today.
Days outside your plan’s window
The summary and the export count only the days your plan keeps records: 30 days on Free, 120 on Essentials and 365 on Enterprise. When the period reaches further back, the page says Part of this period is outside the plan’s window, names the days it left out, and counts only the rest. It never returns a shorter answer as if it were complete. When none of the period is inside the window, no numbers are shown at all.
What the summary shows
- Direct logins: the period’s logins by class, including Not classified. Each login counts on the day it was received, and only SSH, console and
sulogins count. - Findings: findings with a login in the period, as they stand now. Open findings are counted, never left out, along with how many were disposed of, by which decision, and how many were self-reviewed.
- Standing entries: each standing entry in place during the period and how each of its weeks was reviewed: Affirmed, Narrowed, Not reviewed or Week in progress.
- Coverage: the number of servers and of server-days covered, not covered and unknown, and the days not covered by reason. One server on one day is one server-day.
If the summary can’t be loaded, it shows no counts rather than zeros.
Coverage per server per day
Below the summary, Coverage per server per day lists each server on each day with its Coverage, Reason, Reports and Direct logins.
- A day is covered only when every report that day said covered. A day with no report is Unknown.
- On a day that isn’t covered, the number of direct logins is Unknown, never 0.
- Turning detection off for any part of a day makes that day not covered for every server.
- A server counts from the day it was added until the day it was deleted.
For what each reason means and how to fix it, see Direct-login coverage.
Export evidence
Export evidence downloads a ZIP for the days the summary counted. It’s available on Essentials and Enterprise; on Free the button opens an upgrade prompt.
| File | Contents |
|---|---|
logins.csv | One row per login: server, OS account, service, source, the host-reported and received times, class, the finding and its state, claims, and the disposition with its reason, reviewer and time. An open finding’s logins are listed with empty disposition columns |
coverage.csv | One row per server per day, with the state, the reason and the number of reports. The login count reads unknown on every day that wasn’t covered |
summary.txt | The period, the counts, the coverage boundary and what capture cannot see |
The export’s counts equal the summary’s for the same period. Times in the files are in UTC. A reviewer or claimant who has since been removed from the workspace is written as removed member, never by name.
Limits:
- An export holds up to 200,000 direct logins. For more, export a shorter period.
- Each person can export 20 times per hour.
- Exporting needs a person signed in to the console with a role that reads External access. API tokens and service tokens can’t export.
The Logins tab
The Logins tab lists every recorded direct login, newest first, including sudo events, which are recorded but never classified. Each row shows the server, the username, the PAM service, the remote host and when it was received; open a row for its full details.