[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-02。"],[[["\u003cp\u003eThe Risk Analytics dashboard in Google SecOps helps identify unusual behavior and potential risks posed by entities within an enterprise.\u003c/p\u003e\n"],["\u003cp\u003eThe dashboard includes Behavioral Analytics, listing entities by Google SecOps risk scores, and a Watchlist, showing entities based on internal risk calculations.\u003c/p\u003e\n"],["\u003cp\u003eA customizable Risk Calculation Window (24 hours or 7 days) allows users to adjust the risk assessment timeframe for various types of attacks.\u003c/p\u003e\n"],["\u003cp\u003eEntity Analytics allows detailed examination of individual entities, with an Event range window to specify the analysis period up to 90 days, to investigate entity risk over a custom time period.\u003c/p\u003e\n"],["\u003cp\u003eThe Risk Analytics dashboard is useful for various security use cases, such as identifying high data download volumes, suspicious failed login attempts, and dialog messages impersonating Google.\u003c/p\u003e\n"]]],[],null,["Risk Analytics Quickstart guide \nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nLearn how to use the **Risk Analytics dashboard** to identify unusual behavior\nand understand the potential risk that entities pose to your enterprise.\nOn systems that use role-based access control (RBAC), only users with global\nscope can access risk analytics. For more information, see\n[User roles](/chronicle/docs/administration/datarbac-overview#user-roles).\n\nThe Risk Analytics dashboard consists of the following sections:\n\n- **Behavioral Analytics** : lists entities according to [Google Security Operations Entities risk scores](/chronicle/docs/detection/risk-analytics-dashboard#entity_count_risk_score_and_entities_table) risk scores.\n- **[Watchlist](/chronicle/docs/detection/risk-analytics-dashboard#add_a_watchlist)**: lists entities according to internal enterprise risk calculations.\n\nA [Risk Calculation window](/chronicle/docs/detection/risk-analytics-dashboard#adjust_the_risk_calculation_window)\nat the top right changes the calculated risk score displayed in the Risk Analytics\ndashboard. You can change this setting depending on the type of attack you are\nsearching. For example, brute force attacks are more visible by setting the\n**Risk Calculation Window** to **24 Hours** .\nTo see long-term attack, set the **Risk Calculation Window** to **7 days**.\n\nYou can view historical risk scores by selecting a specific date and time in the\ndate selector next to the **Risk Calculation Window**. This displays the\nentity risks calculated for the 24-hour or 7-day window, ending at the chosen\ndate and time.\n\nBefore you begin\n\nTo navigate to the Risk Analytics dashboard, follow these steps:\n\n1. In the navigation bar, click **Detection**.\n2. From **Detection** , click **Risk Analytics**.\n\nBehavioral Analytics\n\nBehavioral Analytics consists of:\n\nThe **Behavioral Analytics** page consists of:\n\n- **Summary Metrics** section: a top-level view of a risk analytics dashboard that lets you investigate risk entities based on Google SecOps entity risk modeling. You can track up to 10,000 entities.\n- **Entities** : a table that complements the existing risk score used for tracking an entity's risk over time, as a metric for detection use cases, and as investigative context. Also called *entity risk metrics* , an entity is a contextual representation of elements in your environment. Examples for entities are user accounts, servers, laptops or phones. You can drill down to each entity by clicking the entity name. This will take you to the **Entity Analytics** page.\n\nFor more information about entities, see\n[Logical objects: Event and Entity](/chronicle/docs/event-processing/udm-overview#logical_objects_event_and_entity).\nFor more information on how risk scores are calculated, see\n[Risk score calculation](/chronicle/docs/detection/risk-analytics-overview#risk_score_calculation).\n\nEntity Analytics\n\nThe **Entity Analytics** page consists of an **Event range** window at the top\nright corner, a **Findings Timeline** section, and a detailed **Findings** table.\n\nSelect a time range to analyze risks\n\n1. In the **Event range** window, select a time range of up to 90 days (\"Last 3 months\").\n2. For **Selection** , click **View analytics for Selection**. This opens a sidebar that shows you the analytics associated with this entity within the selected time range. Each analytic displays an aggregate of all the analytic values within the time range.\n3. Click **View more** to open the corresponding Alerts or Detection view. When detected, an analytic includes a list of related alerts and detections that can be examined further.\n\nView composite detections\n\nThe **Detections** table displays all detections for an entity that\noccurred within the selected time range. An alert is a [composite detection](/chronicle/docs/detection/composite-detections)\nwhen:\n\n- The **Inputs** column shows **Detection** as a source.\n\n- The **Detection type** column displays an **Alert** or **Detection** label\n with a number next to it (for example, `Alert (3)`).\n\nThis indicates that a detection, or a chain of detections, triggered the alert,\nrather than raw events or entities alone.\n\nYou can view and analyze these underlying detections in the **Detections** table\nby using the following features:\n\n- Expand rows to view nested detections, associated event data, and related\n entity information.\n\n- Customize your view by using the column manager to select and arrange\n columns in the table.\n\nFor more information, see [Investigate an alert](/chronicle/docs/investigation/investigate-alert).\n\nUse Cases\n\nHere are a few use cases for the Risk Analytics dashboard.\n\nUse case 1: High download volume\n\nA high download volume of data poses the risk of confidential information leaking.\nGoogle SecOps calculates high risk score numbers for entities\nwith high download volumes.\n\nUse case 2: Suspicious number of failed login attempts\n\nSuspicious numbers of failed login attempts indicate that a hacker or malware is\nattempting to gain access to a user account. Google SecOps will\ncalculate high risk score numbers for entities with suspicious numbers of failed\nlogin attempts. However, if this is done internally, as part of penetration\ntesting, you can\n[modify the entity risk score](/chronicle/docs/detection/risk-analytics-dashboard#modify_an_entity_risk_score).\n\nUse case 3: Dialog message impersonating Google\n\nA dialog message impersonating Google asking to update the Chrome Browser is\nattempting to gain access to user accounts. Google SecOps\ncalculates high risk score numbers for entities where these dialog messages are\ndetected in the code.\n\nWhat's next\n\n- [Modify an entity risk score](/chronicle/docs/detection/risk-analytics-dashboard#modify_an_entity_risk_score)\n- [Investigate an asset](/chronicle/docs/investigation/investigate-asset)\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]