Current Doc

Monitoring Hub

Use Browse Docs to switch sections and search the full docs list.

Documentation

Blue Lantern Security Docs

Learn how to use the marketplace, run security tools, and integrate via the API.

Monitoring Hub

The single place every scan reports to: live activity, your security report, monitor keys, alert rules, and the open items that need attention.

The Monitoring Hub is where the platform's continuous monitoring and your Scan Now runs come together. It has five views, available in the navigation above the page content and in the workspace sidebar. Account settings, integrations, and organization management share the same sidebar.

Overview

The default landing view shows devices reporting in the last seven days, devices needing attention, connected integrations, and alert rules. Below those summaries are open items that need your attention, in two groups. Getting started lists setup steps you have not finished yet, such as adding a Seat License, connecting your email, setting up a device monitor, enabling the daily MFA scan, or creating your first alert; on the Free Tier the items that require a seat are badged. Findings are posture problems from your monitors: devices scored Critical or At Risk, users without MFA, failing mail posture checks, and unmonitored mailboxes. Each task links to the view or page where you fix it. Device findings open the specific report, with remediation steps first; device details, passing checks, and inventory remain available in expandable sections.

Security Report

Your security posture and threat activity at a glance: Monitored Devices, Identity Posture, Mailbox enrollment, Email Health, and Web Traffic. Charts link to their supporting activity, posture report, or member list. Mailbox enrollment describes member configuration, not connection health. No scored email or URL activity is shown as unavailable rather than zero threats. This view also holds the Download attestation report button, which generates the printable Security Attestation Report (account admins only).

Scan Activity

A searchable, filterable table of every run on the account, with the full report a click away.

  • Monitor type: URL, Email, File, Device, Identity, Mail Posture, or AI Exposure.
  • Status: completed, queued, or filtered (an email that an integration's spam rules moved to Spam or Junk automatically; the report still exists).
  • Time range: last 24 hours, 3 days, 7 days, or all time.
  • Verdict: Malicious, Suspicious, or Clean for analysis runs; Critical, At Risk, or Healthy for posture runs.
  • Check results: only runs with at least one failed check, only fully passing runs, or a minimum number of failed checks.
  • Search matches the run's target and description, so you can find a hostname, a subject line, a URL, or a submitter.

Status, submitter, and check-count controls are available under Advanced filters. Enable Latest per device to see each device’s latest run in the chosen date range; verdict and check filters apply after grouping. This view considers up to the most recent 1,000 device scans and shows a notice when that limit is reached. Uncheck it to return to the complete scan history.

Results are paged (25, 50, or 100 per page), and Download CSV downloads the current filtered set, up to 1,000 rows. CSV follows the selected view, including latest-per-device grouping. Each row shows the monitor type, the target, who submitted it, the verdict, and the failed-check count. Clicking a row opens the matching report: email, malware, URL, device, identity, mail posture, or AI exposure.

Monitors

Monitors are scoped keys that let an extension or agent submit scans without any access to the rest of your account: Web Extension (URL runs from the Chrome Monitor), Mail Extension (email runs from the Outlook and Gmail plugins), and Device Monitor (posture scans from the macOS and Windows agents). Each monitor has a display name and, separately, a seat assignment, the seated member its runs bill to and report as the submitter. Last activity is shown when a scan can be matched to the monitor’s ID. Missing activity attribution is labeled unknown and does not mean the monitor is offline. Keys are shown once when created; you can rename or reassign a monitor later without regenerating its key, and revoke it here at any time. Org integrations and the personal Outlook mailbox do not need a monitor key; their connection wizard handles credentials.

Alerts

Start from a critical-device, malicious-content, or daily-flagged-check preset, or create a custom rule. Review the recipient and conditions before saving; selecting a preset alone does not enable an alert. Rules watch completed runs and deliver matches by email or to an HTTP endpoint, immediately or as an hourly or daily digest. See Alerts.

Where runs come from

SourceMonitor typeCadence
Scan Now (web app or API)URL, Email, FileOn demand; 30 free runs a day, 500 per seat
Chrome Monitor, mail pluginsURL, EmailAs you browse and read mail
Google Workspace / Microsoft 365 integrationsEmailReal time, as mail arrives
Personal Outlook mailboxEmailReal time
Device agentsDeviceAbout hourly
CrowdStrike Falcon / Microsoft DefenderDeviceDaily
Identity posture scan (MFA, dormant accounts)IdentityDaily
Mail posture scan (forwarding, inbox rules, mail auth)Mail PostureDaily
AI exposure scanAI ExposureDaily

Personal accounts see a pointer to the Organizations page in the hub header: team monitoring, members, seats, and org-wide integrations live on a shared organization account.

Need Help?

Can't find what you're looking for? Reach out and we'll get back to you.

Contact Support