Skip to main content
Defend shows what Dome detected in production across every Agent. Open Defend in the Console sidebar.

What Feeds Defend

Defend reads runtime events from Targets of type dlp. A dlp Target receives its events from a Dome proxy. It runs no scans, and no Collector reports into it.
Create one with vijil discover deployment-create --name "<name>" --type dlp. See Create and Manage Targets.
With no dlp Target configured, Defend loads and reports no events.

Scope the View

Two controls sit above everything else. Both change every number below them.

Read the Counters

An errored event means the Guardrail failed to reach a verdict, so the traffic passed unchecked. Watch this counter. Unattributed flagged counts detections that Dome failed to tie to a registered Agent. Any number above zero means traffic is routing through the proxy from a source your Agent Registry is missing.
When the window holds more events than the page can chart, the counters and charts use the most recent sample, and each counter shows a Sample badge. Use the command line for exact figures over a busy window.

Read the Charts

Group DLP label totals by Detector to see which rule is firing, or by Agent to see where. An Input detection is something a user sent toward an Agent. An Output detection is something an Agent was about to send back.

Read the Events Table

The table below the charts lists individual detections. Filter it by Input or Output. Expand a row for the full event.

Read the Same Data From the Command Line

Agent runtime events read from the same Target:
See the Discover CLI reference for the full set.

Next Steps

Configure Guardrails

Change what Dome enforces for an Agent.

Observability

Per-Agent Guard execution logs and telemetry.
Last modified on October 2, 2026