> ## Documentation Index
> Fetch the complete documentation index at: https://docs.shieldlabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Analytics

> Find the users, devices, visitors and IP addresses behind your risky traffic, filter them and export the identifications.

<Note>
  This page describes the new analytics dashboard, which is rolling out to all accounts.
</Note>

Analytics is the working table of the analytics dashboard. It lists your users, devices, visitors and public IPs with the band each one earned in the period, and every identification underneath them. Pick a tab, narrow it by band and filters, read the trend, and open any row. It answers three questions: which accounts are risky in this period and why, how risk moved over the period, and which filter isolates the abuse.

<Frame caption="Analytics in the analytics dashboard, Users tab: each user with its band for the period, its identifications, devices, unique visitors and public IPs.">
  <img className="block dark:hidden" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-hero.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=75e8d0e463458b73dda274a9dcadeb51" alt="Analytics in the analytics dashboard on the Users tab for the last 7 days: band pills Trusted 1,100, Suspicious 88 and Dangerous 52, the users chart, and the users table with First seen, Last seen, User HID, Risk, Identifications, Devices, Unique visitors, Public IPs and Public countries." width="2880" height="1762" data-path="images/dashboard/analytics-hero.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-hero-dark.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=a866cbdb9a97f2cfaf69ed5848611a02" alt="Analytics in the analytics dashboard in the dark theme on the Users tab for the last 7 days: band pills Trusted 1,100, Suspicious 88 and Dangerous 52, the users chart, and the users table with First seen, Last seen, User HID, Risk, Identifications, Devices, Unique visitors, Public IPs and Public countries." width="2880" height="1762" data-path="images/dashboard/analytics-hero-dark.png" />
</Frame>

## Five tabs

On screen the tabs read Identifications, Unique visitors, Users, Devices and Public IPs, each with its count for the period. For account-level review, start on **Users**.

| Tab                 | One row per                                                  | Risk shown               |
| ------------------- | ------------------------------------------------------------ | ------------------------ |
| **Users**           | User HID, the account you pass with `checkAuthenticatedUser` | band                     |
| **Devices**         | Device ID                                                    | band                     |
| **Unique visitors** | Visitor ID, one device plus one cookie                       | band                     |
| **Public IPs**      | public IP address                                            | band                     |
| **Identifications** | identification, one check by the snippet                     | its Risk Score, 0 to 100 |

A user, device, visitor or public IP carries the worst band of its identifications in the selected period; only an identification has a numeric Risk Score. Local IPs appear as the optional **Local IP** column of the Identifications tab (add it with **Columns**) and as linked local IPs on each card, with the identifications behind each. [Users, devices, visitors and IPs](/concepts/entities) explains how the identities link.

## Band filters

The pills **Trusted**, **Suspicious** and **Dangerous** show how many rows of the tab fall in each band. Select one or more to filter the table and the chart. On the Identifications tab they filter by each identification's own Risk Score. On an identity tab they filter by the worst band in the period, so **Dangerous** on the Users tab lists every user with at least one Dangerous identification in the period.

<Frame caption="Dangerous users in the analytics dashboard, each with its identifications, devices, unique visitors and public IPs.">
  <img className="block dark:hidden" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-users-bands.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=a86d0e4be7b2676f4c5df9e362b31db9" alt="The Users tab of the analytics dashboard with the Dangerous band pill selected: 52 Dangerous users in the last 7 days, each with its identifications, devices, unique visitors, public IPs and public countries." width="2238" height="1254" data-path="images/dashboard/analytics-users-bands.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-users-bands-dark.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=e837df7f406ab6a1ce7a7db3c608f6b4" alt="The Users tab of the analytics dashboard in the dark theme with the Dangerous band pill selected: 52 Dangerous users in the last 7 days, each with its identifications, devices, unique visitors, public IPs and public countries." width="2238" height="1254" data-path="images/dashboard/analytics-users-bands-dark.png" />
</Frame>

## The chart

The chart shows how the selected tab moved over the period. Its bucket size follows the length of the period. On an identity tab each point counts the unique users, devices, visitors or IPs seen in that bucket, so the points do not add up to the tab's total. Active filters sit on the chart card as chips. Each chip shows its filter as field and value, such as `campaign:spring_promo`, with its count; a High-Risk Events chip shows no count. Remove one with its close button, or clear them all at once.

## Filters

**Filters** opens the list of fields on the left and their values on the right. Pick values, then select **Done** to apply them, or **Reset all** to start over. The fields are High-Risk Events, Country, Browser, OS, Device type, Connection type, Domain, Channel, Source, Campaign, Entry page and Risk signals.

The **High-Risk Events** field filters to one or more of the four events: Multi-accounting, Account sharing, Impossible travel and Account takeover. While this filter is active, a note shows when High-Risk Events were last evaluated.

<Frame caption="Users with a Multi-accounting event in the analytics dashboard.">
  <img className="block dark:hidden" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-users-hre-filter.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=7e6bf860b2155e511c189dd1ee15b5f8" alt="The Users tab of the analytics dashboard filtered to users with a Multi-accounting event, the filter chip high_risk_event:multi_accounting on the chart card: 22 users, 9 Trusted, 6 Suspicious and 7 Dangerous, each with its band, identifications, devices, unique visitors and public IPs." width="2880" height="1742" data-path="images/dashboard/analytics-users-hre-filter.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-users-hre-filter-dark.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=ebc96d7e462f2023a319955e3617e311" alt="The Users tab of the analytics dashboard in the dark theme filtered to users with a Multi-accounting event, the filter chip high_risk_event:multi_accounting on the chart card: 22 users, 9 Trusted, 6 Suspicious and 7 Dangerous, each with its band, identifications, devices, unique visitors and public IPs." width="2880" height="1742" data-path="images/dashboard/analytics-users-hre-filter-dark.png" />
</Frame>

## Saved views

**Views** keeps the filter combinations you use often. Name the current filters and select **Save current view**. A saved view can then be applied with **Apply**, renamed with **Rename**, replaced by the current filters with **Update**, or removed with **Delete**. Saved views are stored with your login, so they follow you to any browser you sign in from.

## The table

On the **Users**, **Devices**, **Unique visitors** and **Public IPs** tabs the columns are First seen, Last seen, the identifier, Risk (the band), Identifications, and how many users, devices, unique visitors, public IPs and public countries are linked to it. A tab leaves out its own count, so the Users tab has no Users column.

On the **Identifications** tab the columns include Date, Identification (the request ID), Visitor ID, Device ID, User HID, Risk Score, Risk signals, Public IP and Country. **Columns** adds Local IP, Local country, Session ID, Cookie ID, Browser, OS, Device type, Connection type, Domain and the traffic source fields: Channel, Referrer Domain, Campaign, Entry page and the UTM parameters. The **High-Risk Events**, **Device risk**, **Visitor risk**, **User risk** and **IP risk** columns are on by default and show a dash in the table; read the user's High-Risk Events and the risk of the user, device, visitor and IP behind each identification on the [identification card](/dashboard/identification-card) and the [user card](/dashboard/entity-card), or clear those columns in **Columns**. On the identity tabs, the **High-Risk Events** and **Risk signals** columns show a dash as well. The **Risk signals** column of the Identifications tab also names informational flags such as Incognito, which add nothing to the Risk Score.

Search finds one identifier. On an identity tab, search by that tab's own identifier. On the Identifications tab, leave the field on **auto** or pick one: request ID, Visitor ID, Device ID, User HID, Cookie ID, Session ID or IP. **Refresh** reloads the first page with the latest data.

## Export

**Export** downloads a CSV of every identification in the current filter, not only the page on screen. On an identity tab the export still holds identifications, one row each. An export covers up to 10,000 identifications; for a larger selection, narrow the period or add a filter. Exporting uses none of your included identifications.

<Frame caption="One account's identifications in the analytics dashboard, ready to export to CSV.">
  <img className="block dark:hidden" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-table-export.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=6b32cf20cc180a55fb0c4fb1171a1e6b" alt="The Identifications tab of the analytics dashboard searched by User HID a91f3c7e5b2d4086: its 12 identifications with Date, Identification, Visitor ID, Device ID, User HID, Risk Score, Risk signals and Channel, one of them Dangerous at 70 with Anti-detect Browser and Proxy, and the Export button." width="2234" height="1252" data-path="images/dashboard/analytics-table-export.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/shieldlabs-725d18f1/JyleDzUFYU3SXP4Q/images/dashboard/analytics-table-export-dark.png?fit=max&auto=format&n=JyleDzUFYU3SXP4Q&q=85&s=c4c54ed3de36a633d58f904938012780" alt="The Identifications tab of the analytics dashboard in the dark theme searched by User HID a91f3c7e5b2d4086: its 12 identifications with Date, Identification, Visitor ID, Device ID, User HID, Risk Score, Risk signals and Channel, one of them Dangerous at 70 with Anti-detect Browser and Proxy, and the Export button." width="2234" height="1252" data-path="images/dashboard/analytics-table-export-dark.png" />
</Frame>

## Open a row

Select the request ID in the Identification column to open that [identification card](/dashboard/identification-card). Select a User HID, Device ID, Visitor ID or Public IP anywhere in the table to open that identity's [card](/dashboard/entity-card). On an identity tab, the identifier in each row opens its card.

## Next steps

<CardGroup cols={3}>
  <Card title="User and device cards" icon="user" href="/dashboard/entity-card">
    One account with its band, its High-Risk Events and everything linked to it.
  </Card>

  <Card title="Identification card" icon="fingerprint" href="/dashboard/identification-card">
    The Risk Score and weighted risk signals of one identification.
  </Card>

  <Card title="Investigate a risky user" icon="magnifying-glass" href="/use-case/investigate-a-user">
    From the Overview to one user card and an action in your backend.
  </Card>

  <Card title="High-Risk Events" icon="triangle-exclamation" href="/features/high-risk-events">
    The four events detected on your users, at Medium or High confidence.
  </Card>

  <Card title="Risk signals" icon="list-check" href="/features/risk-signals">
    Every risk signal you can filter by, with its weight.
  </Card>

  <Card title="Read one account in code" icon="server" href="/api/server-api#read-every-identification-of-one-account">
    Every identification of one account through the History API, by `user_hid`.
  </Card>
</CardGroup>
