> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md).

# Dashboard actions

In the **Dashboards** tab, you can set the date range from which to return data and the refresh rate. In each dashboard you can also do the following.

| Dashboard actions                          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Filter dashboard data                      | <p>You can filter dashboard data by either typing the query in the query bar, or in the relevant widget, by clicking <strong>Filter In</strong>. When clicking <strong>Filter In</strong> the query is added to the query bar. To filter out, delete the query. For example, if you only want to see active incidents that are high severity, in the <strong>Active Incidents by Severity</strong> widget, hover over High and click <strong>Filter In</strong>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>In widgets that group excess results under an <strong>Other</strong> category (such as the <strong>Owners</strong> widget), you cannot use the <strong>Filter in</strong> or <strong>Filter out</strong> options for the <strong>Other</strong> item. Doing so creates a search query that returns no results. To view or filter these excess items, create a custom widget and increase the limit of displayed results or disable the grouping option.</p></div><p><img src="/files/1eglQz8T6aHqdbJQzCcD" alt="dashboards-pivot.png"></p><p>To remove the filter, delete the query.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>If you want to see more information about the data, click the data to take you to the relevant page. For example, in the <strong>Active Incidents by Severity</strong> widget, to see only high incidents, click <strong>High</strong>. This takes you to the <strong>Incidents</strong> page, where you can see all the active critical incidents.</p></div><p>After creating the filter, you can send the URL of the filtered dashboard to other users.</p> |
| Change the color of legend items in graphs | <p>You can change the color of items (such as indicator types and incident types) in some widgets, depending on the widget type and the chart/graph type. When editing a widget, click the item within the legend in the preview window on the right. The <strong>Edit color</strong> option appears and you can select the color for the item.</p><p>If you edit the color after a widget has been added to a dashboard or report, the change only applies to the widget within that dashboard or report. If you edit the widget directly in the <strong>Widgets Library</strong> before adding it to a dashboard or report, the change is applied every time you add the widget to a dashboard or report. Changes to an item within a widget only apply within that widget. For example, changing the color for the <strong><code>Phishing</code></strong> incident type within the <strong>Active Incidents</strong> widget only applies to <strong>Active Incidents</strong>, and not other widgets that contain incident types.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Copy values from graphs                    | In the **Quick chart definitions** window, click an item in the legend and select **Copy value**. This enables copying the value from the widget for commands in the War Room.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Create or edit a dashboard                 | <p>Design a new interface for specific security investigation needs, or edit an existing dashboard. To edit out-of-the-box dashboards, you first need to duplicate them.</p><p>For more information, see <a href="/pages/sz3klPvUR051pUwdQq7q">Manage dashboards</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Import and export a dashboard              | The dashboard is exported as a JSON file. You can make any changes you require and then import the file, for example between test and production environments.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| (Admin only) Define dashboard access       | <p>In a production environment, an administrator defines the default dashboard for each user and selects the default dashboards that the user sees when logging into the tenant, depending on a user’s role. If a user has not modified their dashboard, these dashboards are added automatically, otherwise users can add these dashboards to their existing dashboards. These default dashboards can be removed but not deleted, and can be added again if required.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You cannot add default dashboards to out-of-the-box roles.</p></div><p>For more information, see <a href="/pages/0UsnFetIarc7uZmGyyTV">Manage roles in the Cortex XSOAR tenant</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Share a dashboard                          | <p>Sharing dashboards enables collaboration and alignment among security teams by providing real-time visibility into key metrics and insights, facilitating informed decision-making and coordinated response efforts. Out-of-the-box dashboards and dashboards from content packs cannot be shared unless you duplicate them.</p><p>For more information, see <a href="/pages/sz3klPvUR051pUwdQq7q">Manage dashboards</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Create a report                            | <p>You can generate a report from the dashboard as is, or configure report settings, for example add new widgets to the report, change the report format, and schedule running a report. To create a report from a dashboard, click <img src="/files/V2WwH6VdQije0uWOq37h" alt="cog-wheel-8.png"> and select <strong>Create report</strong>. Click <strong>Run Now</strong> to generate the report.</p><p>For more information, see <a href="/pages/jTXMEh3pAkD8RwhdIaAv">Manage reports</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.6/configure-cortex-xsoar/dashboards-and-reports/dashboards/dashboard-actions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
