Bad Bot Report
Events per Application are by cluster and not application
Threat Type is mostly undefined which diminishes its usefulness
The line graphs are nice in that they save space but aren’t great visualizations as the color values are often similar or a single value dominates so much of the line that you can’t see the other values. Making the colors more distinct and the line thicker may help with this.
Bad Bot Traffic general tab seems pretty useless as it’s just a single line that holds a total of what’s in the other more meaningful tabs.
Bad Bots per Application might be useful if it wasn’t also separating by cluster instead of application.
Endpoints with Bad Bot Traffic is a cool graph, but I feel like there should be more endpoints in it. Being able to export a graph like that with all endpoints seeing traffic per host would be a nice feature.