Skip to content

Home (Threats) ​

The first screen of the admin UI. The sidebar entry is "Home" and the page title is "Threats". It shows counters, the daily budget, firewall statistics, ring latency and a feed of security events. The sections refresh every 10 seconds.

Counters ​

Eight tiles, read from /metrics and /health. The counters come from the Prometheus metrics of the running process, so they start at zero when the process starts.

TileWhat it shows
Requests TodaySum of llm_proxy_requests_total since the process started. It is not reset at midnight
Threats Blockedllm_proxy_injection_blocked_total plus llm_proxy_auth_failures_total
PII Maskedllm_proxy_injection_blocked_total. The proxy exports no count of masked PII; this tile repeats the injection counter
Pass Rate1 - blocked / requests, with the two figures above
Errorsllm_proxy_request_errors_total
Tokensllm_proxy_token_usage_total
Uptimeuptime_seconds from /health
Healthy Endpointspool_healthy / pool_size from /health

The Requests, Threats Blocked and Errors tiles carry a sparkline from /api/v1/metrics/hourly-buckets.

Other sections ​

SectionSource
Needs Attention and Do Next/api/v1/dashboard/summary: open circuit breakers, flagged callers, registry and budget conditions, each with a suggested action
Spend forecast/api/v1/analytics/forecast: today's burn rate projected to the end of the day
Daily BudgetSpend today against budget.daily_limit
ASGI FirewallRequests scanned and blocked, and blocks per signature, from /api/v1/guards/status
Per-Endpoint BreakdownRequests and error rate per endpoint, from /metrics
Ring LatencyP50, P95 and P99 per plugin ring, from /api/v1/metrics/latency
TTFTTime to first token of streamed responses, same source
Ring Execution TimelineThe last 20 request traces, from /api/v1/metrics/ring-timeline
Security PipelineA fixed diagram of the request path

Threat Timeline ​

A Chart.js bar chart with 24 hourly bars and two series, "Blocked" and "Passed".

The chart is filled in the browser from the events of the feed below, one count per event, in the bar of the event's hour. It starts empty each time the page is loaded and holds no history from the server. An event counts as "Blocked" when its level is SECURITY or its message contains BLOCK; every other event of the feed counts as "Passed".

Recent Security Events ​

The feed reads the log stream /api/v1/logs (server-sent events) and keeps the last 50 entries that match one of these conditions:

  • the level is SECURITY, WARNING, ERROR or CRITICAL
  • the message contains one of the words SHIELD, BLOCK, INJECT, PII, FIREWALL, AUTH, RATE, ZT, PANIC, BUDGET

Each row shows the time, the level and the message as logged. A row may offer:

  • Investigate, when the entry has a request id
  • Explain, when the entry names a rule
  • Mute, which hides entries of the same kind. The muted kinds are kept in the browser's localStorage

After more than five consecutive stream errors the feed stops and shows a Reconnect button.

MIT License