Cato Networks Knowledge Base

Generating a Security Events Report

  • Updated

This article describes Cato's Security events reports that highlight the significant data and information related to Cato's Security services for your account.

Overview of Security Events Reports

Cato provides Predefined Report templates that summarize activities in your account for events generated by the Security services in your account. Create the template for the Predefined Report with the sites and SDP users that are included in the report over the defined time range. Then you can generate a report for the defined time range, and download it as a PDF that you can easily share in your organization.

Creating a Predefined Security Events Report

By default, the Predefined Report templates for the Security reports show security data for all sites and SDP users for the past week. You can filter the template to only show specific sites or SDP users in the report.

For more about working with Predefined Reports, see Cato Reports.

PredefinedReports.png

To create a Predefined Report:

  1. From the navigation pane, select Monitoring > Reports.

  2. From the Predefined Reports tab, click New. The Create Report panel opens.

  3. Enter the Report Name for the Predefined Report.

  4. In Type, select Security Report.

  5. (Optional) In Filters, select specific sites or SDP users for the Predefined Report.

    By default, the Predefined Report includes all sites and SDP users.

    To include multiple sites or SDP users in the report, use the IN operator.

  6. Select the Time Range of the report.

    For a Custom range, select start date (From) and the end date (To) for the Predefined Report.

  7. Click Save. The report template is added to the Predefined Reports tab.

    You can also click Save & Generate, and then the report is generated and you can download it from the Generated Reports tab.

Understanding the Security Report

The sections in the report that show the top events for a Security service, show up to the top 12 items for that section.

These are the sections in the Security report:

  • Security Events Summary

    • Blocked Security Events: Graph showing all the block events for the Security engines enabled for your account

    • Top Blocked Events: The top Security engines according to the block events, and the number of events for each engine

    • Top Sites - Security Events (Blocked): Top sites with traffic that generated block events

    • Top Users - Security Events (Blocked): Top users that generated block events

  • Internet Firewall

    • Block and Prompt Events: Graph showing events according to the Prompt, Block, or RBI rule action for the Internet Firewall

    • Allowed Events: Graph showing events for rule with Monitor action that generates events when the Internet Firewall rule is matched

    • Top Blocked Apps: Top apps blocked by the Internet Firewall with the hit count

    • Top Blocked Categories: Top categories blocked by the Internet Firewall with the hit count

    • Top Blocked Domains: Top domains blocked by the Internet Firewall with the hit count

  • WAN Firewall

    • Blocked and Prompt Events: Graph showing block events according to the Prompt or Block rule action for the WAN Firewall

    • Allowed Events: Graph showing events for WAN Firewall rule with Monitor action that generates events when the rule is matched

    • Top Blocked Apps: Top apps blocked by the WAN Firewall with the hit count

    • Top Blocked Categories: Top categories blocked by the WAN Firewall with the hit count

    • Top Blocked Domains: Top domains blocked by the WAN Firewall with the hit count

  • IPS Events

    • Top Threats: Top Threat Names blocked by the IPS service with the number of events for each threat

    • Blocked Events: Graph showing all the block events for the IPS service over the time range of the report

    • Threat Types: Chart showing percentage of the IPS Threat Types that were blocked

    • Risk Level: Chart showing percentage of the Risk Levels for the IPS block events

    • Traffic Direction: Chart showing percentage of the Traffic Direction for the IPS block events

  • Anti-Malware Events

    • Top Detections: Top Threat Names blocked by the Anti-Malware service with the number of events for each threat

    • Blocked Events: Graph showing all the block events for the Anti-Malware service over the time range of the report

    • Threat Types: Chart showing percentage of Threat Type identified by the Anti-Malware service

    • Anti-Malware Actions: Chart showing percentage of actions by the Anti-Malware service

    • Sources with positive detections: List of sources (site or SDP user) for threats detected by the Anti-Malware service

  • Suspicious Activity Events

    • Top Threats: Top Threat Names identified by the SAM engine for the IPS service with the number of events for each threat

    • Monitored Events: Graph showing all the Monitor events for the SAM engine over the time range of the report

    • Threat Types: Chart showing percentage of the Threat Types that were identified by the SAM engine

    • Risk Level: Chart showing percentage of the Risk Levels for the SAM events

    • Traffic Direction: Chart showing percentage of the Traffic Direction for the SAM events

  • DNS Protection Events

    • Threat Types: Chart showing percentage of the Threat Types that were blocked by the DNS Protection engine

    • Top Domains: Top domains blocked by the DNS Protection engine with the hit count

    • DNS Protection Top Hosts: Top hosts that had DNS Protection block events with the hit count

Was this article helpful?

0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.