To generate an alert details report using the Web UI, use the Generate Report form and specify the Alert Details report type.
Note
On a SmartVision Edition appliance, alert details reports can be generated for Malware Object alerts only.
Prerequisites
Admin access to the SmartVision appliance.
To generate an Alert Details report:
Log in to the appliance Web UI and select Reports > Static Reports.
In the Report Type field, select Alert Details.
In the Alert Type field, specify the type of alert for the report:
all
domain-match
infection-match
malware-callback
malware-object
web-infection
Note
On a SmartVision Edition appliance, alert details reports can be generated for Malware Object alerts only.
In the Report Detail field, select the level of detail:
concise—Basic information, such as alert type, alert ID, source IP address, malware name, hostname, and alert URL.
normal—Concise information plus OS changes, callback details, and malware details, if available.
extended—Normal information plus data-theft information (if any) and static analysis details. This format provides all details about files and objects modified during analysis.
In the Report Format field, select the output format for the report:
xml
json
csv
text
In the Time Frame field, select the time period for this report:
past day
past week
past month
past 3 months
between start_date <yyyy>/<mm>/<dd> start_time <hh>:<mm>:<ss> end_date <yyyy>/<mm>/<dd> end_time <hh>:<mm>:<ss>
Click Generate Report.
After the report is generated, the report file name is added to the top of the Generated Reports list.
(Optional) Export the XSD files. These files describe the structure of the Alert Details report.
To export the Windows OS Change XSD, click the Get Windows OS Change XSD link at the top right side of the page.
To export the MAC OS Change XSD, click the Get MAC OS Change XSD link at the top right side of the page.
To export the Alert XSD, click the Get Alert XSD link at the top right side of the page.