Dashboard Widgets
Default ThreatQ Role: Administrative, Maintenance, or Primary Contributor
Custom Role:
- Action Permissions: Objects & Context - Objects (all object types) OR Data Access Permissions: object type
- Action Permissions: Artifact Management - Dashboards
Custom Dashboard Widgets allow you to build interactive dashboards that visualize and monitor threat intelligence data using configurable charts, tables, counters, and descriptive content. Each widget is powered by a data collection and can be customized to present the information most relevant to your analysts and stakeholders.
Available Widget Types
ThreatQ provides the following widget types for custom dashboards:
- Bar Chart – Compare objects across categories.
- Count – Display the total number of matching objects.
- Description – Add formatted text, images, and documentation.
- Line Chart – Visualize trends over time.
- Pie Chart – Display proportional distribution of objects.
- Table – Present detailed object data in tabular format.
Bar Chart Widget
The Bar Chart widget displays object counts grouped by a selected field, making it useful for comparing categories such as sources, tags, or object status.
Users can select individual bars to open the corresponding results in the Threat Library. If grouped by a date or time field (for example, Modified At), dates are displayed in UTC, regardless of the configured user or system time zone.
Objects matching multiple groups are counted once in each applicable group. Objects with scores greater than 10 are included in the 10 score bar.

Widget Parameters
| Field | Description |
|---|---|
| Title | The title that will appear above the widget. |
| Automatically Update | The refresh time for the data. Options include:
|
| Data Collection | Select the data collection to populate the data. |
| Object | Select a specific object type to display. |
| Group By | Select a data column to sort the information such as source, tags, etc. You have the option to group event and custom objects by status and/or point of contact in bar chart widgets. The group by status option is displayed only if an Admin or Maintenance user has configured Event Statuses in the Object Management page.
If you group your bar chart by a date/time, such as grouping by Modified At, the bar chart displays the time in UTC regardless of currently configured system or user timezone display. |
| Visual Display | Select whether to show the bar chart horizontally or vertically. |
| Show Top Options | Select the number of results to display. Options include:
|
Description Widget
The Description widget provides formatted text, images, instructions, or other contextual information that supports the dashboard. It includes a rich text editor for formatting content.
When adding images:
- Add captions after selecting the image alignment.
- Alternative text improves accessibility and is displayed only if the image cannot be loaded.
- Use the editor controls to insert lines above or below an image.
- Resize images to 25%, 50%, 75%, or restore the original size.

Line Chart Widget
The Line Chart widget displays object activity over time using one of the available date metrics.
Supported date metrics include:
- Date Created
- Last Modified
- Expiration Date (Indicators only)

| Field | Description |
|---|---|
| Title | The title that will appear above the widget. |
| Automatically Update | The refresh time for the data. Options include:
|
| Data to Show in Widget | Select the data collection to populate the data. |
| Object | Select a specific object type to display. |
| Date Metric | The date stamp to use with the line chart. Options include:
|
| Time Range | The time range from today to be displayed. Options include:
|
| Time Segments | Select how the dates will be displayed on the line chart. Options include:
|
Count Widget
The Count widget displays the total number of objects matching the selected data collection and object type.
Optionally, the widget can emphasize results using configurable background colors when the count exceeds or falls below a specified threshold.

| Field | Description |
|---|---|
| Title | The title that will appear above the widget. |
| Automatically Update | The refresh time for the data. Options include:
|
| Data to Show in Widget | Select the data collection to populate the data. |
| Object | Select a specific object type to display. |
| Emphasize Data Using Color | Check this box to use different colors to highlight the widget if the count is less than or greater than a specific value. If checked, you will be prompted to select a count value and background color. |
Pie Chart Widget
The Pie Chart widget displays the proportional distribution of objects grouped by a selected field.
Users can click individual segments to view matching results in the Threat Library.
Objects associated with multiple values are counted once in each applicable segment. As a result, the combined percentages may exceed 100%.

| Field | Description |
|---|---|
| Title | The title that will appear above the widget. |
| Automatically Update | The refresh time for the data. Options include:
|
| Data Collection | Select the data collection to populate the data. |
| Object | Select a specific object type to display. |
| Group By | Select a data column to sort the information such as source, tags, etc.
You have the option to group event and custom objects by status and/or point of contact in pie chart widgets. The group by status option is displayed only if an Admin or Maintenance user has configured Event Statuses in the Object Management page. |
Table Widget
The Table widget displays detailed object information in a configurable table.
Users can:
- Open an object by selecting its value.
- Preview object details using the Preview icon.
- Preview or download associated files when they are not malware locked.
Files marked as malware locked cannot be previewed.

| Field | Description |
|---|---|
| Title | The title that will appear above the widget. |
| Automatically Update | The refresh time for the data. Options include:
|
| Data Collection | Select the data collection to populate the data. |
| Object | Select a specific object type to display. |
| Group By | Select a data column to sort the information such as source, tags, etc. |
| Manage Columns | Select the data columns to display in the table. Click the Add Columns option to add more columns to your table. |
| Sorting | Select the column to sort the table and the order (ascending/descending). |
Widget Behavior Notes
Keep the following behaviors in mind when designing dashboards:
-
Widgets automatically refresh based on the configured update interval.
-
Interactive charts allow analysts to drill down into Threat Library results by selecting chart elements.
-
Objects associated with multiple categories may appear in multiple chart segments, causing totals to exceed 100% for pie and bar chart groupings.
-
Time-based bar chart groupings display timestamps in UTC regardless of the user's configured time zone.