Scheduling an Alert Details report using the Web UI

Prev Next

Use the Schedule Report page to generate an Alert Details report on a schedule and send email notifications automatically.

NX_ReportsAlertDetailsReportsSchedule_scap.png

Note

Before you can schedule an Alert Details report to be generated and sent through email, ensure that the SMTP server or domain is configured. You must also specify the email address of the report recipient. For details about configuring these report settings, see the Network Security System Administration Guide.

To schedule an Alert Details report for automatic generation and email distribution:
  1. In the Web UI, choose Reports > Schedule.

  2. In the Scheduled drop-down menu, set the time frequency:

    • hourly

    • daily

    • weekly

    • monthly

  3. In the Time drop-down menu, set the time of day in hours and minutes (00:00).

  4. If you selected a weekly report, specify the report day of the week in the WeekDay field.

  5. If you selected a monthly report, specify the report day of the month in the MonthDay field.

  6. In the Delivery drop-down menu, specify the delivery method. The default delivery is email.

    • email—Deliver the report as a file attached to email.

    • file—Deliver the report as a file linked from the Web UI.

  7. In the Report Type drop-down menu, select Alert Details.

  8. In the Alert Type drop-down menu, select an alert type:

    • malware-object

  9. In the Report Detail drop-down menu, select the level of detail:

    • concise—Basic information, such as alert type, ID, src_IP, malware name, hostname, and alert URL.

    • normal—Concise information plus OS changes, callback details, and malware details, if available.

    • extended—Normal information plus data-theft information (if any) and static analysis details. This format provides all details about files and objects modified during analysis.

  10. In the Report Format drop-down menu, select the output format for the report:

    • xml—Write the report to an XML file.

    • json—Write the report to a JSON file.

    • csv—Write the report to a CSV file.

    • text—Write the report to a text file.

  11. In the Time Frame drop-down menu, select the time period for this report generation:

    • past day—Report covers analysis generated during the past 24 hours.

    • past week—Report covers analysis generated during the past 7 days.

    • past month—Report covers analysis generated during the past 1 month.

    • past 3 month—Report covers analysis generated during the past 3 months.

  12. Click Schedule Report. The scheduled report is added to the top of the scheduling list.

  13. (Optional) Export the XSD files. These files describe the structure of the Alert Details report.

    • To export the Windows OS Change XSD, click the Get Windows OS Change XSD link at the top right side of the page.

    • To export the MAC OS Change XSD, click the Get MAC OS Change XSD link at the top right side of the page.

    • To export the Alert XSD, click the Get Alert XSD link at the top right side of the page.

To delete a scheduled Alert Details report:
  1. In the Web UI, choose Reports > Schedule.

  2. Locate a scheduled Alert Details report that you want to delete.

  3. Click the action icon (action_icon.png) in the Action column.

  4. Click Delete. A prompt for confirmation displays.

  5. Click OK.

    The Alert Details report is removed from the schedule. The following message appears:

  6. Close the message.