Provides reference information about View User Dashboard in Cisco Secure Access. The User dashboard displays endpoint activity for a single endpoint, offering end-to-end visibility for efficient troubleshooting and issue diagnosis.
The User dashboard displays endpoint activity for a single endpoint, offering end-to-end visibility for efficient troubleshooting and issue diagnosis.
User Summary
The User summary section includes the User Details, Device Details, Zero Trust Access, and VPN Access.
View high-level information about the user and their devices that have the ThousandEyes agent installed and registered with Secure Access.
User Details: Shows the identity information such as the full name, email, country, identity provider name, and associated user groups, if available. User group information is pulled directly from your customer active directory (AD) or identity provider (IDP) integration.
Device Details: shows the relevant information for the end user’s device.
Zero Trust Access: shows the status, version, last sync, and certificate issued date.
VPN Access: shows connection status and VPN module version.
Performance
Performance section shows you in real time the endpoint test results for the endpoint user’s data and the application’s data. This allows you to form a baseline of what is normal by viewing trends over time and comparing real time performance to previous performance to see any hop-by-hop path anomalies.
-
Endpoint Test Results drop-down list allows you to select different views for specific endpoint-related data. If you select All then the graph disappears and you only see the Segment visualization section. To see the endpoint and network thresholds see, Endpoint List.
-
Time Range Selector allows you to set the date to view the data history based on the endpoint’s license type. For more information on the test data retention, see Endpoint license usage. The time range selector updates the Endpoint test results graph and the Segment visualization card.
-
Experience score graph is visible when you select All from the Endpoint test results drop-down list. Click on a point in time to see how the endpoint was performing. Time range selector displays up to four days of historical performance data.
-
Endpoint graph shows the CPU and memory of the device.
-
Application score on the graph shows the end-to-end metrics including latency, jitter, loss, and response time.
-
Worst Performance Event Timestamp section is located below the graph. The timestamp shows the date and time when the device experienced its lowest performance. This timestamp is determined by your selected custom date range. If no custom date range is specific, it defaults to showing the worst performance event within the last 12 hours.
-
Top processes drawer shows any process using more than 2% of CPU or memory on an endpoint. The displayed processes correspond to the same time frame as the current endpoint test results graph. Click Top processes to view more information about different running processes.
Security Events
The section displays the allowed and blocked events that occurred when a user's device attempted to access an organizational resource using Zero Trust Access.
The User-associated rules section displays the Zero Trust Access security rules that were triggered by the user's device in a specified period, sorted by descending order of frequency.
-
When an event is both allowed and blocked, its user-associated rule displays as two separate entries in the table.
The Blocked and Allowed Events graphs display the combined total of blocked and allowed Zero Trust Access events for the user's device within the specified time period.
-
To see a comprehensive view of events that are associated with the user, click View all.
The Security event details section shows information for the security event that was triggered for the user's device most recent attempt to access an organizational resource using Zero Trust Access. For more information, see Add a Client-Based Zero Trust Access Posture Profile.
Segment Visualization
The view provides a look at the entire network journey, starting from the agent and ending at the destination, so that you can pinpoint the specific segment that is causing performance degradation. Each segment provides detailed information to troubleshoot underlying network issues.
-
Your ThousandEyes license allows for one scheduled test and one dynamic test. Upgrading your license allows for additional tests. For more information about ThousandEyes licenses, see About Endpoint Agent Tests.
By default, the view covers all tests running on the agent. To filter results by test, use the drop-down menu in the top left corner.
To display the view, click the Applications button.
Segment details
-
Agent—Score is calculated using CPU and memory.
-
Connection—Score expressed as a percentage, indicates how well the wired or wireless connection is performing.
-
Wired connection score—A score of 100% means the link speed is excellent, such as 1 Gbps, reflecting a healthy and reliable connection.
-
Wireless connection score—is calculated using different metrics depending on the operating system, focusing on the quality of the wireless network connection. For more information, see Wi-Fi Descriptions.
-
For Windows:
-
Transmit rate: Data transmission speed between the device and access point. Higher transmit rates generally indicate faster connections.
-
Frame Retry Rate (FRR): The ratio of frames retransmitted to total transmitted frames, indicating wireless transmission reliability.
-
-
For MacOS:
-
Transmit rate: Same as Windows.
-
Signal-to-Noise Ratio (SNR): Calculated as RSSI (Received Signal Strength Indicator) minus Noise level, representing signal quality.
-
-
-
-
Gateway—Score is derived from local network tests to the gateway based on loss, latency, and jitter values.
-
VPN—Score is derived from the local network tests of the VPN that are computed using network metrics including loss, latency, and jitter.
-
ZTA—Shows performance metrics (loss, latency and jitter) to the Secure Access ingress, which represents the unencrypted path over the internet from the client to the ZTA proxy load balancer. Also view performance metrics to the ZTA service, which represents the encrypted path towards the service.
-
Your ZTA version must be 5.17 or higher, as earlier versions lack the necessary telemetry support. Updating ensures full visibility into the secure access path for better monitoring and troubleshooting.
-
-
Internet—Shows the IP addresses that the device data passes through and the delay (similar to how traceroute works).
-
Application—Score reflects the overall performance of the scheduled or dynamic test that is running for an application. Calculated using loss, latency, jitter, and overall HTTP availability and response time.