Generating a report on events

Reports on events are used to collect structured event information for analysis and detection of potential attacks on vulnerable objects.

You can generate the following two groups of reports.

Detailed reports on events

Detailed reports on events are created from displayed event data according to selected filters.

Detailed reports on events support XLSX, CSV formats.

You can generate a report on up to 1 million events at a time (in both formats). If you try to create a report on more events, a file with 1 million records will be generated; the remaining records will not be included in the report.

A detailed report on events represents a table:

  • Title contains columns displayed according to the selected filter.
  • Event information contains a set of events that form a report on all events according to the Source data items. If a custom filter is edited but not saved, the report displays the filter as a PDQL string; a report on selected events contains a set of events selected by the user.

Fields of each event are exported according to the selected filter. Event sorting is also based on the selected filter.

Reports on event statistics

Reports on event statistics are created on the basis of event distribution by source, user, registered outgoing or incoming connection.

Reports on event statistics support PDF, MHT, DOCX formats and consist of several sections:

  • Report parameters displays the name of the selected report, the selected group of assets or all assets, and the selected time interval and filter.
  • Distribution of events by time is a chart that shows the number of events by date, hour, and minute according to the selected time interval. If you generate Event statistics by users reports, this section has the following subsections: User actions, Actions on users, User interactions. The first two sections contain charts by user and events count and a tabular representation. The third section is a tabular representation of users, which specifies the total number of actions in the system. The sections are populated if the values of the subject.name and object.name fields are the same as of the account field.

Generating a report

To generate reports on events:On the main menu, click Events.The Events page opens.Select a group of events on assets.Open a time filter and set an interval for generating the report.
In a detailed report on all events and a detailed report on selected events, time corresponds to the UTC+0 time zone.
Click Generate report.A window opens to select one of the report templates.Select a report template.When the template is selected, the Format box is displayed.Select a report format.Click Generate report.

The website uses cookies according to the cookie policy.