Current ThreatQ Version Filter

Dashboard Widgets

THREATQ REQUIRED PERMISSIONS

Default ThreatQ Role: Administrative, Maintenance, or Primary Contributor

Custom Role:

  • Action Permissions: Objects & Context - Objects (all object types) OR Data Access Permissions: object type
  • Action Permissions:  Artifact Management - Dashboards

Custom Dashboard Widgets allow you to build interactive dashboards that visualize and monitor threat intelligence data using configurable charts, tables, counters, and descriptive content. Each widget is powered by a data collection and can be customized to present the information most relevant to your analysts and stakeholders.

Available Widget Types

ThreatQ provides the following widget types for custom dashboards:

  • Bar Chart – Compare objects across categories.
  • Count – Display the total number of matching objects.
  • Description – Add formatted text, images, and documentation.
  • Line Chart – Visualize trends over time.
  • Pie Chart – Display proportional distribution of objects.
  • Table – Present detailed object data in tabular format. 

Bar Chart Widget

The Bar Chart widget displays object counts grouped by a selected field, making it useful for comparing categories such as sources, tags, or object status.

Users can select individual bars to open the corresponding results in the Threat Library. If grouped by a date or time field (for example, Modified At), dates are displayed in UTC, regardless of the configured user or system time zone.

Objects matching multiple groups are counted once in each applicable group. Objects with scores greater than 10 are included in the 10 score bar.

Bar Chart Example

Widget Parameters

Field Description
Title The title that will appear above the widget.
Automatically Update The refresh time for the data. Options include:
  • every 2 minutes
  • every 5 minutes
  • every 15 Minutes
  • every 30 Minutes
  • ever 60 Minutes
  • Off
Data Collection Select the data collection to populate the data.
Object Select a specific object type to display.
Group By Select a data column to sort the information such as source, tags, etc. You have the option to group event and custom objects by status and/or point of contact in bar chart widgets. The group by status option is displayed only if an Admin or Maintenance user has configured Event Statuses in the Object Management page.

If you group your bar chart by a date/time, such as grouping by Modified At, the bar chart displays the time in UTC regardless of currently configured system or user timezone display.

Visual Display Select whether to show the bar chart horizontally or vertically.
Show Top Options Select the number of results to display. Options include:
  • Top 5
  • Top 10

Description Widget

The Description widget provides formatted text, images, instructions, or other contextual information that supports the dashboard. It includes a rich text editor for formatting content.

When adding images:

  • Add captions after selecting the image alignment.
  • Alternative text improves accessibility and is displayed only if the image cannot be loaded.
  • Use the editor controls to insert lines above or below an image.
  • Resize images to 25%, 50%, 75%, or restore the original size.

Description Widget


Line Chart Widget

The Line Chart widget displays object activity over time using one of the available date metrics.

Supported date metrics include:

  • Date Created
  • Last Modified
  • Expiration Date (Indicators only)

Line Chart Widget

Field Description
Title The title that will appear above the widget.
Automatically Update The refresh time for the data. Options include:
  • every 2 minutes
  • every 5 minutes
  • every 15 Minutes
  • every 30 Minutes
  • ever 60 Minutes
  • Off
Data to Show in Widget Select the data collection to populate the data.
Object Select a specific object type to display.
Date Metric The date stamp to use with the line chart.  Options include:
  • Date Created (all object types)
  • Last Modified (all object types)
  • Expiration Date (indicators only)
Time Range The time range from today to be displayed.  Options include:
  • 1 Week
  • 3 Months
  • 6 Months
  • 1 Year
Time Segments Select how the dates will be displayed on the line chart.  Options include:
  • Days (1 Week Time Range only)
  • Weeks (3 Months, 6 Months, 1 Year only)
  • Months  (3 Months, 6 Months, 1 Year only)
  • Quarters (3 Months, 6 Months, 1 Year only)
    Quarters will return the following results based on Time Range selection:
    • 3 Months will display the current quarter plus the previous quarter
    • 6 Months will display the current quarter plus the previous two quarters.
    • 1 Year will display the current quarter plus the previous four quarters.

Count Widget

The Count widget displays the total number of objects matching the selected data collection and object type.

Optionally, the widget can emphasize results using configurable background colors when the count exceeds or falls below a specified threshold.

Count Example Count Example 2

Field Description
Title The title that will appear above the widget.
Automatically Update The refresh time for the data. Options include:
  • every 2 minutes
  • every 5 minutes
  • every 15 Minutes
  • every 30 Minutes
  • ever 60 Minutes
  • Off
Data to Show in Widget Select the data collection to populate the data.
Object Select a specific object type to display.
Emphasize Data Using Color Check this box to use different colors to highlight the widget if the count is less than or greater than a specific value.
If checked, you will be prompted to select a count value and background color.

Pie Chart Widget

The Pie Chart widget displays the proportional distribution of objects grouped by a selected field.

Users can click individual segments to view matching results in the Threat Library.

Objects associated with multiple values are counted once in each applicable segment. As a result, the combined percentages may exceed 100%.

Pie Chart Example

Field Description
Title The title that will appear above the widget.
Automatically Update The refresh time for the data. Options include:
  • every 2 minutes
  • every 5 minutes
  • every 15 Minutes
  • every 30 Minutes
  • ever 60 Minutes
  • Off
Data Collection Select the data collection to populate the data.
Object Select a specific object type to display.
Group By Select a data column to sort the information such as source, tags, etc.

You have the option to group event and custom objects by status and/or point of contact in pie chart widgets. The group by status option is displayed only if an Admin or Maintenance user has configured Event Statuses in the Object Management page.


Table Widget

The Table widget displays detailed object information in a configurable table.

Users can:

  • Open an object by selecting its value.
  • Preview object details using the Preview icon.
  • Preview or download associated files when they are not malware locked.

Files marked as malware locked cannot be previewed.

Table Widget

Field Description
Title The title that will appear above the widget.
Automatically Update The refresh time for the data. Options include:
  • every 2 minutes
  • every 5 minutes
  • every 15 Minutes
  • every 30 Minutes
  • ever 60 Minutes
  • Off
Data Collection Select the data collection to populate the data.
Object Select a specific object type to display.
Group By Select a data column to sort the information such as source, tags, etc.
Manage Columns Select the data columns to display in the table.  Click the Add Columns option to add more columns to your table.
Sorting Select the column to sort the table and the order (ascending/descending).

Widget Behavior Notes

Keep the following behaviors in mind when designing dashboards:

  • Widgets automatically refresh based on the configured update interval.

  • Interactive charts allow analysts to drill down into Threat Library results by selecting chart elements.

  • Objects associated with multiple categories may appear in multiple chart segments, causing totals to exceed 100% for pie and bar chart groupings.

  • Time-based bar chart groupings display timestamps in UTC regardless of the user's configured time zone.