Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

FDM-Managed device executive summary reports

Want to summarize with AI?

Log in

Explains how to use the FDM-Managed device Executive Summary Report to review operational statistics, generate network operation data, analyze overview, network assessment, and threat details, and create a PDF report.


An executive summary report is a collection feature that

  • offers operational statistics for all FDM-managed devices

  • compiles data hourly after initial report generation, with Security Cloud Control taking up to two hours to collect information from the Firewall Device Manager after device onboarding, and

  • generates data when network traffic triggers an access rule or policy on an FDM-managed device.

Configuration requirements and display features

Report information is not part of the request for events, so events and reports are not available at the same cadence. We strongly recommend that you enable malware defense and IPS licenses, as well as file logging for access rules, in order to allow a device to generate the events that are reflected in the reports.

All information displayed in the report is dependent on the Time Range toggle button located at the top of the page. Policies may experience varying traffic or triggers during the time range you select.

After a device is onboarded to Security Cloud Control, event data is automatically collected. The data that is collected is dependent on the device configuration. The license that is delivered with all FDM-managed devices does not support all the options within the Network Operations Report. We recommend the following configurations for the devices you want to collect data from:

  • Malware Events: Enable the malware Smart License.

  • Security Intelligence: Enable the Smart License.

  • IPS Threats: Enable the Smart License.

  • Web Categories: Enable the URL Smart License.

  • Files Detected: Enable the Smart License.

Note

The executive summary does not inherently include traffic that is flowing over VPN.

The report includes several display tabs:

  • Overview tab: Displays visuals from triggered rules, threats, and file types. These items are displayed numerically, with the largest or most frequently hit rules, events, or files listed first.

  • Network Assessment tab: Addresses web site categories and detected file types. This display captures only the top ten most frequently encountered categories and file types.

  • Threats tab: Displays statistics generated by intrusion events—Top Attacker captures the originating IP address of an event, Top Target captures the destination IP address of an event, and Top Threats captures the type of events that have been categorized as a threat.

Malware events represent detected or blocked malware files only. Note that the disposition of a file can change, for example, from clean to malware or from malware to clean. We recommend that you Schedule a Security Database Update to keep your devices up to date with the latest intrusion rules (SRUs).

Top Ten Access Rule Hits offers three tabs you can toggle between to view the top ten rule transfers, connections, or rules that blocked packets.

Other than selected time range, you cannot use the Network Assessment tab to determine when a specific web category or file type was detected.

The Threats tab also provides details about the threats and malware types that are detected.

After you configure the report to your preference, generate a PDF of the report. See Manging Reports for more information.


Generate FDM-Managed device executive summary reports

Generate executive summary reports to analyze the most impactful malware, threats, and impacted security intelligence on your network.

Security Cloud Control provides several reports that you can use to analyze the impact of your security policies on the traffic going through your FDM-managed devices. An Executive Summary Report summarizes the most impactful malware, threats, and impacted security intelligence. Security Cloud Control polls devices every hour to collect events. To learn more about what the executive summary offers, see FDM-Managed Device Executive Summary Report.

The FDM-managed device reports are available only on the FDM-managed device that is currently onboarded to your tenant. These reports are generated hourly and are not part of the request for events. So events and reports are not available at the same cadence. After initially onboarding your FDM-managed device, Security Cloud Control may take up to two hours to generate reports. Until there are reports to display, the Reports tab under the Analytics option will not be visible.

If you are a Security Analytics and Logging subscriber, Network Reports do not reflect the events forwarded to the Secure Event Connector (SEC).

Note

The data used in traffic-related reports is collected from events triggered by access control rules and other security policies. The generated report does not show traffic for rules in which logging is not enabled, or rules that have not been triggered. Ensure that you configure your rules with the information that matters to you.

Procedure

1.

In the navigation pane, click Analytics > Executive Summary Report.

2.

Select the time range for the reports—24 Hours, 7 Days, 30 Days, or 90 Days.

3.

(Optional) Click the filter (The device executive summary report highlights key performance metrics and operational status for the selected device, providing insights for management and decision-making.) icon to select a custom list of devices, for which to generate a report.

4.

Click Generate Report (PDF).

5.

To save the report as a PDF, click Save and choose Save as PDF in the Destination drop-down.

6.

Browse to the location in which you want to save the report, and click Save. If you do not want to save the report, click Cancel at any time.

The executive summary report is generated and saved as a PDF to your specified location.