> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/operations/dashboards-and-reports/creating-a-custom-dashboard-rux.md).

# Dashboard creation best practices

Plan, build, and maintain Vectra dashboards using live data, visualizations, and AI-assisted SQL.

## Introduction

Custom Dashboards help Vectra users monitor security posture, spot risks, and move from summary data into investigation.

Vectra dashboards bring important security data into one view. They help teams monitor posture, identify threats, and move into investigation without switching between reports or tools.

A strong dashboard helps users make faster decisions. A weak dashboard creates noise and makes analysts search for what matters.

**A great dashboard should answer two questions immediately: What is happening and what should I do next?**

* Show threat activity, risk trends, and entity status at a glance.
* Connect KPI numbers to investigation workflows.
* Use rich text widgets to explain what to look for and why it matters.
* Combine AI-generated and manually written SQL queries into one clear view.
* Give each audience the right level of detail.

{% hint style="warning" %}
**Common Dashboard Mistakes**

* **Too many widgets:** Aim for 8–12. For complex analyst dashboards, keep it under 16.
* **No clear audience:** Executives and analysts need fundamentally different views
* **Missing context:** A number without a trend, target, or explanation is just a number
* **Duplicate metrics:** The same data shown in multiple chart types wastes attention
* **Makes the next action clear**: Make the next action clear—investigate, review, escalate, or confirm that no action is needed. If it is not clear, simplify the dashboard or add context.
  {% endhint %}

## Dashboard best practices at a glance <a href="#dashboard-best-practices-at-a-glance" id="dashboard-best-practices-at-a-glance"></a>

{% stepper %}
{% step %}

#### [Start from an existing Vectra dashboard](#id-1.-start-from-an-existing-dashboard)

Duplicate and customize rather than building from scratch.
{% endstep %}

{% step %}

#### [Define your goal before you build](#id-2.-define-your-goal-before-you-build)

Every widget should answer a question or support an action.
{% endstep %}

{% step %}

#### [Dashboard structure best practices](#id-03.-dashboard-structure-best-practices)

**Lead with the most important information**

* Put key values and summary information first, then trends and investigation detail.

**Add context**

* Explain what users are looking at, why it matters, and what they should do next.

**Name everything clearly**

* Use descriptive dashboard, section, and widget names.

**Pivot to more detailed investigation**

* Configure **Investigate further** where users need to move from summary to detail.
  {% endstep %}

{% step %}

#### [Choosing the right content](#id-04.-choosing-the-right-content)

* What belongs and what doesn't belong to a Dashboard.
* Make widgets respond to dashboard filters
  {% endstep %}

{% step %}

#### [Widget types and visualization](#id-5.-widget-types-and-visualization)

* Use the chart type that makes the answer easiest to understand.
* Use AI to get started, then refine with SQL when needed.
* Review and simplify over time. Remove content that no longer helps users make decisions.
  {% endstep %}
  {% endstepper %}

***

## 1. Start from an existing dashboard

The fastest way to build a good dashboard is to start from one that already works.

Vectra dashboards are already structured with the right hierarchy, labels, and widget types for common security use cases. Duplicate one, then customize it for your audience.

{% hint style="success" %}

## **Recommended approach: start from an existing dashboard and customize it** <a href="#recommended-approach-start-from-an-existing-dashboard-and-customize-it" id="recommended-approach-start-from-an-existing-dashboard-and-customize-it"></a>

Choose a Vectra dashboard that is close to your goal. Duplicate it, then adjust the data, names, labels, and guidance for your team.

* **Keep the structure:** KPIs first, trends next, investigation tables near the bottom.
* **Customize the data:** Update SQL or AI-generated queries for your entities, time ranges, and data sources.
* **Rename to your context:** Use your team’s terms for the dashboard name, section names, and widget labels.
* **Add your context:** Use rich text widgets for playbook notes, MITRE references, links, and escalation guidance.
  {% endhint %}

<figure><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fm54jNzknaHQkEO5ElU7x%2Fimage.png?alt=media&amp;token=6bd24992-d4a7-41a9-85e6-d07197cf42a8" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}

## Get started in 3 steps <a href="#get-started-in-3-steps" id="get-started-in-3-steps"></a>

1. Go to **Dashboards** in the left navigation
2. Find the **Best Practice Example Dashboard** or another Vectra dashboard close to your use case.
3. Open the **three-dot menu (⋮)** and select **Duplicate**. Then rename and customize it.
   {% endhint %}

## 2. Define your goal before you build

Answer these four questions before adding widgets. Use the answers to create a short text widget at the top of the dashboard.

#### The four planning questions <a href="#the-four-planning-questions" id="the-four-planning-questions"></a>

1. **What is the purpose?** Monitor posture, track threat trends, support incident response, report to leadership, or investigate a specific data source.
2. **Who is the audience?**

   <table data-header-hidden><thead><tr><th width="138.89453125"></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Audience</strong></td><td><strong>What they need</strong></td><td><strong>Best widget types</strong></td></tr><tr><td><strong>Executives</strong></td><td>Risk posture, trend direction, key KPIs</td><td>Single Value, Spiral, Donut</td></tr><tr><td><strong>Security managers</strong></td><td>Team performance, alert volume, response times</td><td>Line, Bar, Scorecard, Stack Bar</td></tr><tr><td><strong>Analysts</strong></td><td>Detailed entity data, query results, investigation paths</td><td>Table, Heatmap, Bar with drill-down</td></tr><tr><td><strong>Operators</strong></td><td>Real-time monitoring, threshold alerts, active entities</td><td>Single Value, Map, Table with filters</td></tr></tbody></table>
3. **What questions must it answer?** Examples: “How many high-risk entities are active?” “Which entities have the most detections?” “Has detection volume changed over time?”
4. **What action should viewers take?** Every dashboard should lead somewhere: a triage queue, an investigation, an escalation decision, or a clear “no action needed.”

{% hint style="info" %}
**The 30-second rule**

Can users answer their main question in under 30 seconds? If not, simplify the dashboard or improve the hierarchy. Write down the top three questions before building.
{% endhint %}

## 3. Dashboard structure best practices <a href="#id-03.-dashboard-structure-best-practices" id="id-03.-dashboard-structure-best-practices"></a>

Use sections to guide users from summary to detail. The section structure creates the dashboard’s hierarchy.

<figure><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FXVoebXu0x1M5dJBxBSK8%2Fimage.png?alt=media&amp;token=2814f034-11dd-40d9-bc71-905c663648b9" alt=""><figcaption></figcaption></figure>

#### Recommended section order (example) <a href="#recommended-section-order-example" id="recommended-section-order-example"></a>

1. **Primary answer above the fold**\
   Answer the dashboard’s main question in the first visible area.
2. **Security posture summary**\
   Use Single Value widgets to show what is happening now.
3. **Trend analysis**\
   Use line and bar charts to show whether conditions are improving or getting worse.
4. **Entity and risk analysis**\
   Use charts and ranked tables to show where users should focus.
5. **Investigation tables**\
   Use detailed tables with “Investigate further” configured.
6. **Test CSV export for table widgets.** If a table widget will be shared with stakeholders, verify that its CSV export contains the expected fields and values.
7. **Context and playbooks**\
   Add rich text guidance, MITRE references, links, and escalation criteria.

<figure><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FHRpIPFeZIU3zeUGXLGSt%2Fimage.png?alt=media&amp;token=ee6182a4-4feb-401e-bf38-d816f7e214fe" alt=""><figcaption></figcaption></figure>

#### Use titles and descriptions to create structure <a href="#use-titles-and-descriptions-to-create-structure" id="use-titles-and-descriptions-to-create-structure"></a>

Use widget titles and descriptions to explain what users are looking at, what they should investigate, and why it matters.

| Do                                                                                                                                                                                                                                 | Don't                                                                                                                                                                                                                             |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>Name every section clearly</li><li>Put Single Value widgets first</li><li>Add context before widgets when needed</li><li>Make the most important widget the most prominent</li><li>Keep related widgets together</li></ul> | <ul><li>Use names like “Section 1.”</li><li>Lead with investigation tables</li><li>Mix unrelated data without labels</li><li>Give every widget equal visual emphasis</li><li>Exceed 12–16 widgets on a single dashboard</li></ul> |

#### Using the Content panel

The Content panel lists the dashboard’s named sections. On long dashboards, users rely on it to jump directly to the information they need.

Use section names that describe the content, such as **Threat posture summary** or **High-risk entities**. Avoid generic names such as **Section 1** or **Tab name**.

**The 5-second test**

Show the dashboard to a colleague for five seconds, then ask:

* “What is this tracking?”
* “What would you do if something looked wrong?”

If they cannot answer, improve the section names, hierarchy, or supporting context.

#### Widget count guidelines

| Executive / summary    | 4–8   | Risk score, top threats, trend, critical entities         |
| ---------------------- | ----- | --------------------------------------------------------- |
| Operational monitoring | 8–12  | Alert volume, entity analysis, response time, tables      |
| Analyst investigation  | 12–16 | Multi-source, detailed tables, drill-downs, playbook text |

## 4. Choosing the right content <a href="#id-04.-choosing-the-right-content" id="id-04.-choosing-the-right-content"></a>

Not every metric belongs on a dashboard. Include only what helps the audience understand, decide, or act.

#### What belongs on a Vectra dashboard <a href="#what-belongs-on-a-vectra-dashboard" id="what-belongs-on-a-vectra-dashboard"></a>

* **Threat and risk KPIs:** Total alerts, risk scores, active investigations, high-risk entities
* **Trends:** Alert volume over time, risk score trajectory, detection patterns by data source
* **Threshold alerts:** Entities exceeding risk scores, critical severity detections
* **Filters:** Time frame, data source, entity type — give analysts context control
* **Rich text context:** What to look for, why it matters, MITRE references, hyperlinks, code snippets
* **Investigation tables:** Configured with "Investigate further" so analysts can act directly

#### Make widgets respond to dashboard filters <a href="#make-widgets-respond-to-dashboard-filters" id="make-widgets-respond-to-dashboard-filters"></a>

Dashboard filters only affect widgets that are configured to use them. When creating or editing a widget, make sure its SQL includes the relevant dashboard filter variables after the `WHERE` clause.

`-- AND {timeRange}`

`-- AND {cloudtrail.filters}`

`-- AND {contains}`

Use the variables that are relevant to the widget. Some filter variables are dynamic and depend on the dashboard filters currently available.

**Best practice:** If a widget intentionally should not change with dashboard filters, leave it unfiltered. Otherwise, configure it so users get consistent results when they adjust the dashboard.

<figure><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F9gNx8nVpdcqc6qoGmYEe%2FSQL%20add%20widget.png?alt=media&amp;token=bd5e290b-23d2-46cd-b8f4-79e0362389ac" alt=""><figcaption></figcaption></figure>

#### What does not belong <a href="#what-does-not-belong" id="what-does-not-belong"></a>

* Avoid large raw-data tables. Configure “**Query for investigate further clickthrough”** when creating or editing a widget for deeper analysis.
* The same metric shown in several chart types
* Metrics with no owner or next action
* Charts that do not answer a clear question

<figure><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F3Bd3uC1nR2OAjZHMvwAt%2Finvestigate%20further%20custom%20SQL.png?alt=media&amp;token=827ca8a7-a611-480e-bc6c-3d3da5ab1d44" alt=""><figcaption></figcaption></figure>

## 5. Widget types and visualization

Choose the widget type based on the question you need to answer.

<table data-header-hidden><thead><tr><th width="103.15234375"></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Widget</strong></td><td><strong>Purpose</strong></td><td><strong>Network-focused example</strong></td><td><strong>User takeaway</strong></td><td><strong>Example</strong></td></tr><tr><td><strong>Line chart</strong></td><td>Shows change over time so users can spot increases, drops, or unusual patterns.</td><td>Detection volume by severity over the last 30 days.</td><td>“Is network activity getting better, worse, or changing suddenly?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F2bG4LxEu9R8FvPDMWTnU%2Fimage.png?alt=media&amp;token=36cde1d6-d015-4c64-8059-7b486e10561d" alt="" data-size="original"></td></tr><tr><td><strong>Sparkline / compact trend</strong></td><td>Shows a small trend when space is limited.</td><td>7-day trend for high-risk host count.</td><td>“Is this metric moving in the right direction?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FxiXD1EsUpMtm0TC6iAlb%2Fimage.png?alt=media&amp;token=d5588fea-5a68-42b9-80f7-f504133aa733" alt="" data-size="original"></td></tr><tr><td><strong>Area chart</strong></td><td>Shows volume over time with more visual weight than a line chart.</td><td>Total network detections over time.</td><td>“How much activity is happening, and when did it peak?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FXXprNGf686c3dGO2um5G%2Fimage.png?alt=media&amp;token=66ea5b13-6d41-4d05-8deb-47d2a61238b2" alt="" data-size="original"></td></tr><tr><td><strong>Scatter plot</strong></td><td>Shows relationships or outliers across two measures.</td><td>Hosts plotted by detection count and risk score.</td><td>“Which entities stand out from normal behavior?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FOORHpGTVix1rbhT7VwM4%2Fimage.png?alt=media&amp;token=95b439e1-a5f5-42ef-b4d8-4a6eab1598af" alt="" data-size="original"></td></tr><tr><td><strong>Bar chart</strong></td><td>Compares categories so users can see what ranks highest.</td><td>Top 10 hosts by detection count.</td><td>“Where should I focus first?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F7pEOS5KKxDeyQGM8mlkB%2Fimage.png?alt=media&amp;token=f83b1b05-df90-4b32-8af6-ab29fac1e696" alt="" data-size="original"></td></tr><tr><td><strong>Stack bar</strong></td><td>Shows how categories change together over time.</td><td>Weekly detections grouped by severity.</td><td>“Is the mix of activity changing, or is one severity level driving the trend?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F6cm4C1oFvLZtdSQQeCDp%2Fimage.png?alt=media&amp;token=ee93b1d9-22f8-4c1a-b5f7-9d232594c314" alt="" data-size="original"></td></tr><tr><td><strong>Histogram</strong></td><td>Compares values across categories or time buckets.</td><td>Detection count by data source.</td><td>“Which source is producing the most activity?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FSDvENI5rTW0TevgthxEt%2FHistogram.png?alt=media&amp;token=da83d759-939d-4c7f-8d6f-d9eb8e543728" alt="" data-size="original"></td></tr><tr><td><strong>Heatmap</strong></td><td>Shows dense patterns across two dimensions.</td><td>Detection frequency by host and day of week.</td><td>“Where are repeated patterns concentrated?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F5TeI73fFCbgHnAVFv5RL%2Fheatmap.png?alt=media&amp;token=3f5b68cc-000a-4406-b0fc-8329e063d1ff" alt="" data-size="original"></td></tr><tr><td><strong>Donut / Pie</strong></td><td>Shows a simple breakdown of a whole into a few parts.</td><td>Detections by severity: critical, high, medium, low.</td><td>“What is the overall distribution?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2Fywv03YoMn3YsiTt2WITb%2Fdonut%3Apie.png?alt=media&amp;token=b352c533-c0c6-46b8-b70f-f2f21ea19ea4" alt="" data-size="original"></td></tr><tr><td><strong>Table</strong></td><td>Shows detailed records users can investigate.</td><td>Recent detections with host, severity, timestamp, and source.</td><td>“Which specific entities or detections should I open?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F7c0v1Cilkobhp88txRld%2FTable.png?alt=media&amp;token=8c4da26f-8e7a-4958-91f1-0b56d2775277" alt="" data-size="original"></td></tr><tr><td><strong>Sankey</strong></td><td>Shows movement or relationships between sources and destinations.</td><td>Internal hosts communicating with external destinations.</td><td>“Where is activity flowing?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2F34QM13gXpfFLUdEojxg8%2FSankey.png?alt=media&amp;token=7ee29121-66c1-402a-bb3a-e65cfbf08d22" alt="" data-size="original"></td></tr><tr><td><strong>Map</strong></td><td>Shows activity by location when geography matters.</td><td>Network detections by source country or region.</td><td>“Is activity coming from unexpected locations?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FYUZgxtYo2VN0tDZVqb7s%2FMap.png?alt=media&amp;token=24bd373f-fe66-445d-b1ce-f52ece0b9373" alt="" data-size="original"></td></tr><tr><td><strong>Single Value</strong></td><td>Shows one important number users need to understand immediately.</td><td>High-risk hosts detected in the last 24 hours.</td><td>“Is there something urgent I need to look at now?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FZgPiM3dhP14ysrmerGI6%2FSingle%20Value.png?alt=media&amp;token=7746c454-ac9d-4c81-8a7b-bc5f3d27941a" alt="" data-size="original"></td></tr><tr><td><strong>Spiral</strong></td><td>Shows cyclical or repeating time patterns.</td><td>Detection activity by hour across multiple days.</td><td>“Is there a recurring pattern?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FTmvv8QNshjcWyzEArMme%2Fimage.png?alt=media&amp;token=4496b93e-1eb5-4c54-9a7b-65b2a4994bfe" alt="" data-size="original"></td></tr><tr><td><strong>Gauge</strong></td><td>Shows progress or status against a threshold.</td><td>Current risk score compared with an escalation threshold.</td><td>“Is this metric within an acceptable range?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FK3FjaQ0O5lOUtR1rLFnD%2FGauge.png?alt=media&amp;token=dbe553ad-da24-4b1e-bec4-43ca4ff4ecf9" alt="" data-size="original"></td></tr><tr><td><strong>Network graph</strong></td><td>Shows relationships between entities.</td><td>Host-to-host communication paths around a suspicious entity.</td><td>“What is connected to this entity?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FUJpWjAOWrTgQLLhFMr0M%2FNetwork%20Map.png?alt=media&amp;token=b998b32d-1172-4311-af00-27cf704db72a" alt="" data-size="original"></td></tr><tr><td><strong>Text</strong></td><td>Adds guidance, definitions, links, and playbook context.</td><td>Notes explaining what to investigate in a suspicious host activity section.</td><td>“What does this mean, and what should I do next?”</td><td><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FoEsujVz98xRSO4PyntDa%2FText.png?alt=media&amp;token=d4e6dd8f-1279-433c-b878-01090a0d9828" alt="" data-size="original"></td></tr></tbody></table>

#### Creating widgets: AI assistant or SQL editor <a href="#creating-widgets-ai-assistant-or-sql-editor" id="creating-widgets-ai-assistant-or-sql-editor"></a>

When you click **Add Widget**, Vectra offers two paths to create a widget query.

<figure><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FvIo8M0z3vUmRGU6re8o8%2Fsteps.png?alt=media&amp;token=1f2ca73a-1e18-4391-9edd-f4341362e059" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4227135129-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHJ1ltuWFvsArFWtevnRn%2Fuploads%2FyU6PNCLuqI2CHXN6Pny8%2Fcreate%20widget.png?alt=media&amp;token=a8cca262-4c67-436a-8d35-25e20f3a10d6" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**When to use AI vs. SQL**

* **Use AI assistant for a fast starting point**, common security queries, or early exploration.
* **Use SQL editor for exact logic**, joins, custom filters, and detailed query changes.
* **Use both**: Start with AI Assisted Query, then refine the generated SQL in the SQL Editor.
  {% endhint %}

## Ready to build? <a href="#ready-to-build" id="ready-to-build"></a>

The fastest path to a great dashboard is to find one that's close to your goal and duplicate it. Go to Dashboards, find the **\[Sample] Discovery Dashboard**, duplicate it, and start from there.

1. Navigate to **Dashboards** in the left nav (under Hunt)
2. Find the **\[Sample] Discovery Dashboard** — or any Vectra dashboard matching your use case
3. Click ⋮ → **Duplicate**, then rename and customize for your team

[Go to Dashboards ↗](https://portal.vectra.ai/discover/all)\
[View Best Practice Example Dashboard ↗](https://portal.vectra.ai/discover/best-practice-example-dashboard)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/operations/dashboards-and-reports/creating-a-custom-dashboard-rux.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
