Each report contains the results of at least one filter. Each filter has a single object type (event or finding). You define the filter criteria, and the scope of the data included, including which fields are included and the time frame. You can also define how the data is sorted and grouped.
From the navigation pane, select .
Click Create Report to display the Report Details page.
In the General section, set these general parameters:
Enter a report name and a brief description of the report.
From the Format drop-down list, select the required format (CSV, PDF, or XML).
(Optional) Click Upload Logo File to include a logo in the report, then select the image file and click Open.
In the Scheduling section, set when and how often to run the report:
Select Scheduling Enabled.
Set one of these frequency options:
Daily at — Runs the report each day at the hour selected from the drop-down list.
Weekly on — Runs the report on each of the selected weekdays. Runs the report on each of the selected weekdays.
Monthly every — Runs the report on the selected month.
By Cron expression — Runs the report according to the input timing expression.
Run Only Once — Runs the report one time only.
(Optional) To receive an email when the report is ready, select Send Notification by Email to, then enter the recipient email addresses. Use semicolons to separate multiple addresses To attach the report to the email message, select Attach Report.
In the Filter section, set the filter criteria:
In the Headline field, enter a brief name for the filter.
From the Object Type drop-down list, select the type of objects to include in the report ( Events or Findings).
From the Detail Level drop-down list, select the report type:
Details — Contains all field data.
Summary — Contains only the number of results or widgets.
In the filter fields, enter a query, then set the time frame for the report data.
Note
Click Estimate for an indication of the number of items the report would return.
In the Limit Report items field, set the maximum number of items to include in the report.
Note
By default, the maximum number of items for each filter section is 5,000.
Click Sort by, then select the field according to which you want the data to be sorted and select Ascending of Descending to set the sort direction.
Click Group by, then select the field according to which you want to group the data.
Note
If you use the Group by option with a Summary filter, the report returns a count of the results for each group. If you use the Group by option with a Summary filter and widgets, a single widget is returned for each filter (and not for each group within the filter).
(Optional) Click Add Filter to define an additional filter section to the report.
Click Save.
(Optional) Click Run.
RESULT_6489F34C2EBB4FE5B4F7B9D35AE92EB0 The report and its run status are listed in the Reports table.