Argus2026.01
Connector & Coverage Health

What Argus can see —
and what it can't.

Deployment-readiness snapshot: which data sources are connected and flowing, and how much of the estate has defensive instrumentation Argus can reason over.

Appliance
argus-acme-01
As of
2026-05-31 08:00Z
Connectors
5 / 7 active
Coverage
91% assessed
Deployment readiness

Signal health


Connectors active
5 / 7
Events ingested (24h)
80.6k
Hosts assessed
226 / 248
No-coverage hosts
2
Pull connectors & receivers

Data source status


SourceTypeStatusLast syncEvents (24h)Mode
WazuhEDR & vulnerabilityConnected2m ago12,400Agent
Microsoft 365Identity & mailboxConnected6m ago3,100OAuth · read-only
AWSSecurity Hub · GuardDutyConnected4m ago880IAM role · read-only
GCPAudit · IAMConnected9m ago420SA key · read-only
Nginx / ApacheWeb access logsConnectedlive63,800File tail
Syslog (UDP/TCP)Generic receiverIdle0Listening
CEF / LEEFFirewall & applianceNot configured
Action for deployment. Point the firewall's CEF/LEEF syslog at the listening receiver (:15140) to light up the perimeter signal — the only configured-but-idle source. All pull connectors are healthy and read-only.
Instrumentation

Coverage distribution


Well covered
159
Medium
44
Low
21
None
2

226 of 248 hosts have been assessed for defensive instrumentation. 159 are well covered; 2 have no coverage at all — including one crown-jewel datastore.

22 hosts remain unassessed pending their first full scan in the new segment.

Priority gaps

Blind spots that matter most


HostHostnameCoverageGapAFS
10.30.9.2db-finance-01NoneNo EDR, no log forwarding — crown jewel79.3
10.20.4.7stg-app-07NoneNo endpoint telemetry detected84.0
10.10.2.40file-srv-09LowSyslog only; no EDR41.0