tencent cloud

Web Application Firewall

Overview Statistics

Download
Modo Foco
Tamanho da Fonte
Última atualização: 2026-08-03 16:49:34
Traduzido por IA

Feature definition

The Overview Statistics page displays aggregated data for the current domain across dimensions such as API assets, risk events, and sensitive data exposure through various visualizations like metric cards and statistical charts, helping you quickly grasp the overall API security posture.

Prerequisites

1. You have purchased a WAF yearly/monthly subscription instance and enabled API security.
3. You have enabled the API security switch for the corresponding domain on the Domain Onboarding page. After it is enabled, the analysis is expected to be completed within 30 minutes, after which relevant statistical data will be displayed.


Use Cases

Scenario
Description
Daily Security Operations
Quickly view the overall API security posture and detect abnormal trends.
Event investigation
Conduct in-depth investigation into sensitive data involvement and event distribution through the deep analysis module.
Reporting and presentation
Present API security status to management through visual charts.

Operation Step

Note:
In the upper-right corner of the API Security page, click Usage scenes to view the tutorial on using the API Security feature.
1. Log in to the WAF console. In the left sidebar, choose API Security > Overview Statistics.
2. Click the domain drop-down list in the upper-left corner of the Overview Statistics page and select the domain you want to view. Alternatively, you can select All Domains.
3. The upper part of the Overview Statistics page displays the API assets and API security risks. Each metric shows its current value and the change compared to the previous day.
API assets
Metric Value
Description
Total APIs
Total APIs under the current domain. Click to jump to the Asset Management page to view all APIs.
Discovered APIs
Number of APIs with the asset status of newly discovered under the current domain. Click to jump to the Asset Management page and filter APIs with the asset status of Detected.
Active APIs
Number of API assets accessed in the past 7 days under the current domain. Click to jump to the Asset Management page and filter APIs with the activity status of Active.
Inactive APIs
Number of API assets not accessed in the past 7 days under the current domain. Click to jump to the Asset Management page and filter APIs with the activity status of Deactivate.
API security risks
Metric Value
Description
Unsafe APIs
Number of API assets with low-risk, medium-risk, high-risk, or ultra-high-risk levels under the current domain. Click to jump to the Asset Management page and display APIs with the risk levels of Low risk, Medium risk, High risk or Extreme high risk.
Sensitive APIs
Number of API assets that transmit sensitive data under the current domain. Click to jump to the Asset Management page and display sensitive APIs.
Security events
Total API risk events under the current domain. Click to jump to the Risk Event page.
4. The Overview Statistics page allows you to select a time range. After filtering, all statistical data on the page, except for the API assets and API security risks, is redisplayed according to the specified time range.
Note:
The data displayed on the Overview Statistics page is updated every 30 minutes.
5. The middle section of the Overview Statistics page displays the TOP5 domain rankings across three dimensions using horizontal bar charts. Hover over a bar to view the complete domain name. Click View API Assets to navigate to the Asset Management page and view the APIs under that domain.
Chart
Description
Top 5 active APIs by domain
The top 5 domains by request volume.
Top 5 sensitive APIs by domain
The top 5 domains by number of sensitive APIs.
Top 5 domains by API security events
The top 5 domains by number of associated security events.
6. The middle section of the Overview Statistics page displays two modules: Top 5 Active APIs and Active/Inactive API trends.
Active API TOP5: Displays the top 5 API assets with the highest call volume for the currently selected domain within the specified time range.
Click API Asset Management to navigate to the Asset Management page.
Click See More to view the TOP10 / TOP50 / TOP100 active API assets.
Active/Inactive API Trend: Displays the trend of active and inactive API counts for the current domain within the selected time range using a line chart.
7. Multiple analysis charts are displayed in the lower-right section of the Overview Statistics page to facilitate in-depth security assessment.
Module
Description
Sensitive APIs by sensitivity
Displays the distribution of sensitive APIs by sensitivity level (low/medium/high).
Top 5 sensitive APIs
Displays an API ranking sorted by the volume of sensitive data. Hover to view the complete API. Click View API Asset to jump to the asset management page and view the details of that API.
Types of sensitive data
Displays the distribution of sensitive data types by Tag (e.g., ID card number/phone number). Click View All Sensitive APIs to jump to the asset management page and view all sensitive APIs.
Discovered API security events by severity
Distribution of alarm levels (low/medium/high) for newly discovered assets.
Top 5 API security events
Displays an interface ranking sorted by the number of associated events. Hover to view the complete API. Click View API Asset to jump to the risk events page and view the event details of that API.
Event types
Displays the distribution of events by category (e.g., permission exceptions/business exceptions/Web attacks). Click View All Events to jump to the risk events page and view all event types.
API event trends
Displays the fluctuation trend of newly discovered events over time. Click View All Events to jump to the risk events page and view all event types.

Ajuda e Suporte

Esta página foi útil?

comentários