Generating Security Events Reports

Overview of Security Events Reports

Cato provides Predefined Report templates that summarize activities in your account for events generated by the Security services in your account.

Create the template for a recurring or one-time report with the sites and SDP users that are included in the report over the defined time range. By default, the Predefined Report template for the Security Events report shows traffic and data for all sites and SDP users for the past week.

For more about working with reports, see Cato Reports.

Creating a Recurring Security Events Report

Create a new recurring report by defining the Filters for the items included in the report, as well as the Schedule which defines how often the report is generated - daily, weekly, or monthly. Generated reports are stored in the Cato Cloud, and they can be automatically emailed or downloaded. The Schedule also defines the time range that is covered by each report.

You can select the Mailing List of email addresses for the recipients, which can include Cato Management Application admins and external users.

For more information about Mailing Lists, see Working with Mailing Lists.

To create a scheduled Security Events report:

  1. From the navigation pane, select Home > Reports.
  2. From the Catalog tab, select the template you want to use to generate the report.
  3. Click Generate > Create Schedule.
  4. Enter a Report Name.
  5. (Optional) In Filters, select specific sites or users for the Predefined Report.

    By default, the Predefined Report includes all sites and users.

    To include multiple sites or users in the report, use the IN operator.

  6. Define when the report will be generated and sent:
    1. Select the Frequency that the report is automatically sent: Daily, Weekly, or Monthly.
    2. For Weekly and Monthly Scheduled reports, in Every select the day that the report is sent.
  7. In Send to Mailing List, select the Mailing List that receives the report.

    You can click New to create a new mailing list.

  8. Click Save Schedule. The report is added to the Saved Reports tab.

Generating a Recurring Report On Demand

Recurring reports are automatically generated based on their schedule settings. For example, a weekly report configured for Monday, is generated every Monday. You can also choose to manually generate a recurring report on demand, in which case the generated report uses the defined time range based on the current day. If an admin manually generates a weekly report on a Tuesday, the time range for the report is the previous 7 days starting from that Tuesday, regardless of the starting day of the recurring report. For more information about the time range of recurring reports, see Cato Reports.

To generate a recurring report on demand:

  1. From the navigation pane, select Home > Reports.
  2. From the Saved Reports tab, find the recurring report and click Generate Now.
  3. From the Generated PDFs tab, find the report and click Download.

Creating a One-Time Security Events Report

You can create a one-time report based on the Security Events template. You define the Filters for the items included in the report.

To create a One-Time report:

  1. From the navigation pane, select Home > Reports.
  2. From the Catalog tab, select the template you want to use to generate the report.
  3. Select Generate > Generate Now.
  4. Enter a Report Name.
  5. In Filters, define the Timeframe and Timezone of the report.
  6. Click Generate, the report is generated and you download it from the Generated PDFs tab.

Understanding the Security Report

The sections in the report that show the top events for a Security service, show up to the top 12 items for that section.

These are the sections in the Security report:

  • Security Events Summary

    • Blocked Security Events: Graph showing all the block events for the Security engines enabled for your account
    • Top Blocked Events: The top Security engines according to the block events, and the number of events for each engine
    • Top Sites - Security Events (Blocked): Top sites with traffic that generated block events
    • Top Users - Security Events (Blocked): Top users that generated block events
  • Internet Firewall

    • Block and Prompt Events: Graph showing events according to the Prompt, Block, or RBI rule action for the Internet Firewall
    • Allowed Events: Graph showing events for rules with Monitor action that generates events when the Internet Firewall rule is matched
    • Top Blocked Apps: Top apps blocked by the Internet Firewall with the hit count
    • Top Blocked Categories: Top categories blocked by the Internet Firewall with the hit count
    • Top Blocked Domains: Top domains blocked by the Internet Firewall with the hit count
  • WAN Firewall

    • Blocked and Prompt Events: Graph showing block events according to the Prompt or Block rule action for the WAN Firewall
    • Allowed Events: Graph showing events for WAN Firewall rule with Monitor action that generates events when the rule is matched
    • Top Blocked Apps: Top apps blocked by the WAN Firewall with the hit count
    • Top Blocked Categories: Top categories blocked by the WAN Firewall with the hit count
    • Top Blocked Domains: Top domains blocked by the WAN Firewall with the hit count
  • IPS Events

    • Top Threats: Top Threat Names blocked by the IPS service with the number of events for each threat
    • Blocked Events: Graph showing all the block events for the IPS service over the time range of the report
    • Threat Types: Chart showing the percentage of the IPS Threat Types that were blocked
    • Risk Level: Chart showing percentage of the Risk Levels for the IPS block events
    • Traffic Direction: Chart showing percentage of the Traffic Direction for the IPS block events
  • Anti-Malware Events

    • Top Detections: Top Threat Names blocked by the Anti-Malware service with the number of events for each threat
    • Blocked Events: Graph showing all the block events for the Anti-Malware service over the time range of the report
    • Threat Types: Chart showing the percentage of Threat Type identified by the Anti-Malware service
    • Anti-Malware Actions: Chart showing percentage of actions by the Anti-Malware service
    • Sources with positive detections: List of sources (site or SDP user) for threats detected by the Anti-Malware service
  • Suspicious Activity Events

    • Top Threats: Top Threat Names identified by the SAM engine for the IPS service with the number of events for each threat
    • Monitored Events: Graph showing all the Monitor events for the SAM engine over the time range of the report
    • Threat Types: Chart showing the percentage of the Threat Types that were identified by the SAM engine
    • Risk Level: Chart showing the percentage of the Risk Levels for the SAM events
    • Traffic Direction: Chart showing percentage of the Traffic Direction for the SAM events
  • DNS Protection Events

    • Threat Types: Chart showing the percentage of the Threat Types that were blocked by the DNS Protection engine
    • Top Domains: Top domains blocked by the DNS Protection engine with the hit count
    • DNS Protection Top Hosts: Top hosts that had DNS Protection block events with the hit count

Was this article helpful?

0 out of 0 found this helpful

0 comments