Template catalogue
Templates are the prepared questions reporting is built from. They live in the product, ship with the release, and cannot be created or edited — you build datasets over them.
43 templates are included: 16 presets (we lay them out; they export to PDF) and 27 tables (you choose the presentation; they export to PDF, CSV and XLSX). See Overview for what that distinction means.
Reading the tables below:
- Views — the alternative cuts a preset offers over the same data. Tables have none; their presentation is yours.
- Period — yes means the template takes a time window. point-in-time means it is a snapshot of how things are right now, and offers no period at all.
Device administration over TACACS+ and RADIUS.
| Template | Type | Views | Period |
|---|---|---|---|
| AAA activity & trend | Preset | full · hourly | yes |
| AAA overview | Preset | full · totals | yes |
| Policy & command insights | Preset | policy · commands | yes |
| RADIUS device usage | Preset | usage | yes |
| TACACS+ device usage | Preset | usage | yes |
| AAA policy | Table | — | point-in-time |
| RADIUS accounting | Table | — | yes |
| RADIUS authentication | Table | — | yes |
| RADIUS profiles | Table | — | point-in-time |
| TACACS accounting | Table | — | yes |
| TACACS authentication | Table | — | yes |
| TACACS authorization | Table | — | yes |
| TACACS+ profiles | Table | — | point-in-time |
| TACACS+RADIUS authentication | Table | — | yes |
The two device usage presets are worth calling out: they rank your busiest devices and your quietest, including devices that made zero requests in the window. A device that has stopped authenticating produces no log rows at all, so it can only be spotted from the inventory side — which is what these two do.
TACACS authorization makes the authorized command visible and groupable, so “which commands are people actually running” is a chart rather than a log trawl.
802.1X port access, endpoints, guests and certificates.
| Template | Type | Views | Period |
|---|---|---|---|
| NAC access overview | Preset | overview · rejects | yes |
| NAC certificate posture | Preset | overview | point-in-time |
| NAC sessions | Preset | live · history | yes |
| Endpoint groups | Table | — | point-in-time |
| Endpoints | Table | — | point-in-time |
| Guest sessions | Table | — | yes |
| NAC active sessions | Table | — | point-in-time |
| NAC authorization profiles | Table | — | point-in-time |
| NAC policy | Table | — | point-in-time |
| NAC session history | Table | — | yes |
NAC access overview carries a day-by-hour heatmap of authentications, which answers “when” in a way a daily total cannot — a burst of rejects at 03:00 looks nothing like the same count spread across a working day. Its rejects view is the forensic cut: reasons, the NAS devices doing the rejecting, and the MAC addresses being rejected.
NAC certificate posture buckets the internal CA’s certificates by time to expiry — expired, within 7 days, 30, 90, and valid — so an expiry wave is visible before it becomes an outage. Only metadata is ever projected; private keys and signing requests are never readable through reporting.
Guest sessions is deliberately careful with personal data: aggregation is offered only over non-personal dimensions, and the sponsor’s email and company are hidden by default.
Configuration Tracker
Section titled “Configuration Tracker”The configuration collection engine and its history.
| Template | Type | Views | Period |
|---|---|---|---|
| NCM collection health | Preset | full · trend | yes |
| NCM change activity | Preset | overview | yes |
| NCM JIT activity | Preset | overview | yes |
| Collection sources | Table | — | point-in-time |
| Tracked configs | Table | — | point-in-time |
NCM change activity answers what actually moved in a period: how many snapshot versions were cut, across how many configs, the top churn, the text-versus-binary split and which version labels were applied.
NCM JIT activity covers just-in-time credential behaviour — passwords minted and rotated, leases live now, and how many mints were exposed to a standalone collector. It never projects credential plaintext.
System
Section titled “System”The platform itself: inventory, health, accounts and the audit trail.
| Template | Type | Views | Period |
|---|---|---|---|
| Authentication failures | Preset | overview | yes |
| Inactive users | Preset | list | point-in-time |
| Platform inventory | Preset | aaa · nac | point-in-time |
| System Health & Fleet | Preset | live · activity | yes |
| Activity log | Table | — | yes |
| Device groups | Table | — | point-in-time |
| Devices | Table | — | point-in-time |
| Log exclusions | Table | — | point-in-time |
| Network objects | Table | — | point-in-time |
| RBAC roles | Table | — | point-in-time |
| Syslog destinations | Table | — | point-in-time |
| User groups | Table | — | point-in-time |
| Users | Table | — | point-in-time |
Authentication failures is the cross-surface one, and the most useful single preset for a security review. It puts failures from all three sign-in surfaces side by side — the admin UI, device administration (AAA), and port access (NAC) — as rates rather than raw counts. That is deliberate: NAC volume dwarfs UI volume by orders of magnitude, so raw counts on one chart would hide the very thing you are looking for. Each surface keeps its own axis.
Inactive users lists the longest-dormant accounts, with accounts that have never signed in ranked first — the correct answer for an access review, and one a plain sort would bury at the bottom.
Alerts
Section titled “Alerts”| Template | Type | Views | Period |
|---|---|---|---|
| Alerts overview | Preset | overview · compact | yes |
Open, critical and firing counts, the severity mix, the resolved-versus-firing lifecycle split, the top sources and conditions, and a feed of the most recent openings.