QS-WAN · Security Dashboard

Network security monitoring that counts events, not bytes

Network security monitoring in QS-WAN is one screen. Gateways online, users connected, and the traffic on the gateway over the last five minutes, split inbound and outbound, each with a current value and a peak. Beside it, a feed of security events, totalled and broken out by category.

What it is

What this is, before anybody sells anything

QS-WAN is the console that runs your gateways, your VPN users and the agent on each machine. The Security Dashboard turns what those three do into events you can count, in two halves kept apart on purpose.

Two halves

The live half

The Monitoring snapshot. Gateways online, users connected, and gateway traffic over the last five minutes, inbound and outbound tracked separately, each with its current value, its peak and the gateways feeding it. Five minutes is the whole window: it is a speedometer and it does not pretend otherwise.

The counted half

The security event feed. Every event lands there with a severity and a status, and the total splits four ways: Gateway and VPN, Certificates and TLS, Endpoint protection, Compliance. Four buckets, because those are what break.

Throughput is a different question, answered by network traffic monitoring. This page is about events and detections, and about the one thing a chart of either cannot tell you on its own.

The mechanism

The part most network security monitoring tools skip

Most consoles have one way to show nothing: an empty chart. A quiet network and a dead collector look identical on the wall, and you find out which one three weeks later. Press a button on the panel and watch the two come apart.

Gateways VPN users Endpoint agents Ingest worker Reading Not reading Byte offset Suppressed 3 Monitoring snapshot Online gateways and connected users Gateway traffic, last 5 min Security events 24 Detection feed Gateway & VPN 9 Certificates & TLS 6 Endpoint protection 5 Compliance 4 Response rules you set The snapshot is live. The feed is counted, and kept 90 days.
Live. Events arriving and counted.

The diagram shows three sources publishing into one ingest worker: gateways, VPN users and the agent on each machine. The worker reads, counts what it took in and counts what it suppressed, and feeds a security event feed whose total splits four ways into Gateway and VPN, Certificates and TLS, Endpoint protection and Compliance. A second path runs straight to the monitoring snapshot, which is live and does not pass through the worker. Press Quiet hour and the feed stops climbing while the worker keeps reading. Press Reader stops and the feed stops climbing in exactly the same way, except that now the worker is reading nothing, which is the difference an empty chart cannot show you. Press Silence a rule and one category stops counting while the suppressed count climbs, so a quieter feed is explained rather than believed.

That is why the ingestion state is on the page. The byte offset says how far the console has read, the last ingestion time says when it last read anything, and the suppressed count says how much you chose not to see. Suppression is the setting everyone turns up and nobody writes down, so silenced rules are listed as silenced.

Why this exists

Four things that go wrong without it

Four consoles and twenty minutes

A tab for the firewall, one for the antivirus, one for the VPN, one for the servers. Four places to read before anybody can say what happened, and four chances to stop reading early.

Connected users counted by squinting at a session list

A list you scroll is not a number you can act on. The contractor who got access on Friday is only visible to whoever happens to land on the right line.

A certificate that lives in a calendar reminder somebody set in 2024

Expiry is a task while there is still time to do it, and an outage afterwards. A reminder sitting in a calendar you cannot see is what decides which of the two it becomes.

Is anything wrong right now, answered with probably not

Without a count there is no answer, only an impression, and an impression is what you are left defending when somebody asks again in March.

What you gain

Network security monitoring software that two people read differently

If you run the network

The gap arrives while it is still a task

The certificate nobody saw expire arrives in the Certificates and TLS bucket while there is still time to do something about it. The contractor who got access on Friday shows up in connected users, on a count you did not assemble.

And a complaint that the network is slow meets a number. The last five minutes, inbound and outbound, with the peak beside the current value, which is either an answer or a reason to look further.

If you sign for it

One renewal instead of four

One console covers gateways, users, endpoints and configuration risk, which is one renewal instead of four and one place an auditor gets taken in March.

Events are kept 90 days. What happened in July still has an answer in October, and it is the same answer for everybody who asks.

How it works

Three steps to a counted event

The endpoints and gateways publish

The agent on each machine publishes what it sees and Host Endpoint Monitoring takes it in. The per device counters and the rolling graph behind them belong to network traffic monitoring, not to this page. The Network Scanner dispatches scans through a gateway: five presets from host discovery to a vulnerability audit, six timing templates, and recurrence of one time, daily, weekly or monthly.

The console counts what arrived, and says what did not

Ingestion is shown as a number rather than assumed: total ingested, total suppressed, the byte offset the console has read to, and the last ingestion time. Alert volume is counted at 24 hours, 5 days and 90 days, which are the windows on the graph rather than a promise about how long anything is held.

You govern the noise in Management

The Management tab tunes ingestion: retention at 90 days, noise controls, suppressed rules, trusted IPs, configuration risks you have reviewed and accepted, notification channels, automatic response rules, and a log of what they did.

Before you start

You need the QNova Client on the machines you want host telemetry from, and a gateway the scanner can reach. Both are already part of QS-WAN, so there is nothing new to install before the first event is counted.

In detail

What you are looking at, once it is counting

Feed

What the four buckets are telling you

Every event lands in the feed with a severity and a status. You never have to decide which bucket an event belongs to, because the bucket is the first thing it gets, and the total is always the four added up:

  1. Gateway and VPN
  2. Certificates and TLS
  3. Endpoint protection
  4. Compliance

Four buckets, because those are what break. A spike in the total says which of the four to open, which is the whole reason the total is split at all.

Alert volume is counted at 24 hours, 5 days and 90 days, and events are kept 90 days.

Scans

What you dispatch through a gateway

The Network Scanner sends a scan out through a gateway rather than from the machine you are sitting at. Five presets, from host discovery to a vulnerability audit. Six timing templates, from the slowest and quietest to the fastest. Recurrence of one time, daily, weekly or monthly.

An offline gateway leaves a scheduled intent, not a result. The console records what you asked for and runs it when the gateway is back, which is a different thing from a scan that silently did not happen.

Latest scans and open ports sit on the same dashboard as the feed, so what the scanner found and what the agents reported are read in one place rather than reconciled in two.

Where this earns its place

Four mornings this changes

The morning somebody says the network is slow

One screen instead of four tabs. Inbound and outbound for the last five minutes, with the peak beside the current value, so the complaint meets a number in the time it takes to look.

The certificate nobody saw expire

It arrives in the Certificates and TLS bucket while it is still a task, rather than reaching you through whoever could not connect this morning.

The contractor who got access on Friday

They show up in connected users, on a count you did not have to assemble by hand, on the same screen you were already looking at.

The auditor who asks what happened in July

Events are kept 90 days, and the report composer builds one PDF from the sections you choose, with the same scope and window applied to every one of them.

Works better together

The other tiles on the same screen

These are not a related links box. Each one owns a tile beside this one, and each answers a question this page deliberately does not.

01

The telemetry that fills most of the feed: alerts, rules, hosts, authentication, and the ingestion state this page keeps pointing at.

02

Answers how much is moving. This page answers what happened, and how bad it was. Two questions, two screens, on purpose.

03

Looks at the same company from the outside, and puts what it finds on the same dashboard as everything the inside reported.

04

Turns configuration risk into a number that moves, so a gap you have been carrying has a price you can point at.

The auditor side of the same events is a use case of its own, compliance management software, and every feature is listed in one place.

What this does not do

The limits, because they are what make the rest believable

Nobody of ours is watching your screen

This is a product, not a managed service. No analysts of ours read your events at three in the morning, and we do not sell that. You get the console, the counters and the rules you set yourself.

It does not see an endpoint that is not reporting

Host telemetry comes from the agent on each machine. No agent, no host telemetry, and the ingestion state is where you check that rather than where you assume it.

The Network Scanner needs a reachable gateway

An offline gateway leaves a scheduled intent, not a result. The scan is recorded as something you asked for, and it converges when the gateway comes back.

Five minutes is five minutes

The snapshot is a live window, not a traffic history. If the question is what the line was doing last Tuesday, that belongs to network traffic monitoring, not here.

Questions people ask

The ones that come up first

What is network security monitoring?

It is watching a network for security events rather than volume: failed logins, certificate problems, endpoint detections, configuration drift. Here that is the Monitoring snapshot for now, and an event feed, split four ways and kept 90 days, for what happened.

Is this network security monitoring software, or a service?

Software. You run it. We do not watch your network for you and we do not staff a room of analysts. The response rules are yours to set, and the log shows what they did.

How is this different from network traffic monitoring?

Traffic monitoring answers how much is moving. This answers what happened, and how bad it was.

Can I stop a noisy rule from filling the feed?

Yes, and it stays visible. Suppressed rules are listed as suppressed and trusted IPs as trusted, so a quiet feed gets explained instead of believed.

How long are events kept?

Retention is 90 days. The alert volume graph has its own windows of 24 hours, 5 days and 90 days, which are how far back the graph draws, not a second retention promise.

Bring your four consoles. We will show you the one screen.

An engineer, a console shaped like yours, and as long as you need. You watch the event total split four ways, the ingestion state underneath it, and five minutes of gateway traffic. It is free and there is nothing to sign.

Scroll to Top