Cisco Secure Access Help

PDF

Cisco Secure Access Help

Security Activity Report

Want to summarize with AI?

Log in

Describes Security Activity Report in Cisco Secure Access. The Security Activity report highlights security events generated by your organization's sources visiting destinations flagged—but not necessarily blocked—by Secure Access security researchers as a threat.


The Security Activity report highlights security events generated by your organization's sources visiting destinations flagged—but not necessarily blocked—by Secure Access security researchers as a threat. Activities captured by this report include attempts to access sites hosting malware or phishing sites, botnet activity on infected machines on your local network, and attempts to download malicious files.


View Activity and Details by Filters

The Security Activity report gives you the ability to monitor and discover threats to your organization by displaying traffic patterns. You can filter these results by event type, category, time period, and type of request.

Note
Secure Access reports are time-dependent. Secure Access time is UTC by default but can be changed to a different timezone on a per-user basis. Navigate to Admin > Accounts and update your account's time setting.

Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Security Activity .

    The Security Activity Home interface.
  2. Click the calendar drop-down and choose a time period of events to view. You can generate a report to document activities for a specific time period. You can select from the predefined ranges for the last 24 hours, the previous calendar day (yesterday), the last seven days, and the last 30 days.


    The Security Activity Date Filter interface.

    To choose a custom time period:

    1. Click Custom range.

      The Security Activity Date Filter Custom interface.
    2. Click the calendar icons next to the From and To fields, and then select the desired start and end dates.
      The system allows you to choose a maximum of 30 days time period from the last 90 days.
      Note
      The timezone is always set to UTC.
    3. Click APPLY to generate the report for the selected custom range.
  3. Choose which security event types or categories you want to view in the report. By default, all events and categories are selected to display activity for all event types.

    • Antivirus Disposition is Malicious—Lists events that have been filtered through a virus scan.

    • Cisco AMP Disposition is Malicious—Lists events that have been filtered through Cisco Advanced Malware Protection (AMP).

    • Security Category—Lists events allowed or blocked against selected security categories: Command and Control, Crypto mining, Malware, Phishing, and Other Categories (Contains Dynamic DNS, Newly Seen Domains, and Potentially Harmful).


    The Event Type interface.
  4. For Response, select Allowed, Blocked, or both.

    Note
    If you select Antivirus Disposition is Malicious or Cisco AMP Disposition is Malicious as the Event Type, you cannot select Response > Allowed. Secure Access cannot allow viruses to pass through the system. These will always be blocked.
    The Sec Act Response Filter interface.

What to do next

Once all filters have been selected, the activity graph and event details will reflect the chosen filters. The graph will display activities for the events selected during the configured time period. The event details cards will stack from most recent to oldest.

The Security Activity 30 Days interface.

Hovering over a bar on the graph shows details for that time period (the hour or day). Clicking the details redirects you to the Activity Search report where you can view further details for that time period filtered by Response (if only one is selected) and the security categories selected.


The Sec Act Graph Detail interface.

View Activity and Details by Event Type or Security Category

If you want to view data for individual event types or security categories in your environment to see which categories may pose more risk and at what times depending on trends, use the Group Events by Type feature.


Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Security Activity.


    The Security Activity interface.
  2. Choose a time period of events to view. You can generate a report to document activities for the last hour, the last 24 hours, the previous calendar day (yesterday), the last seven days, or the last month.


    The Time Period interface.
  3. Select which security event types or categories you want to view in the report. By default, all events and categories are selected to display activity for all event types.


    The Group Events interface.
  4. For Response, select Allowed, Blocked, or both.

    Note
    If you select Antivirus Disposition is Malicious or Cisco AMP Disposition is Malicious as the Event Type, you cannot select Response > Allowed. Secure Access cannot allow viruses to pass through the system. These will always be blocked.

    AMP Disposition is Malicious as the Event Type, you cannot select Response Allowed. Secure Access cannot allow viruses to pass through the system. These will always be blocked.

What to do next

The activity graph updates to show each selected event type so you can compare activities for each type of security risk. You can click the event type on the graph or in the filter to view or hide the events in the graph.


The Sec Act Category Graph interface.

Grouping security categories also reorganizes the events' details cards by event type. By viewing event details by event type or category, you can see which categories were more active and perhaps causing more risk to the environment.


The Sec Act Category Shuffle interface.

Group Security Categories

When Group Security Categories is unchecked, the selected security categories are shown individually on the Activity graph. This enables you to view which categories had more activity within the given time frame or where spikes in some categories occurred. Clicking the category name on the graph or in the Security Categories filter will show or hide that category's events on the graph.


The Sec Act Graph Categories 2 interface.

Rolling over a point on the line graph provides a summary of the security events at that time by the categories selected. Clicking the details redirects you to the Activity Search report where you can further view the activity's details.


The Sec Act Category Details interface.

View an Event's Details

In the Security Activity report, you can view the details of a security event, including date and time, destination, identity, and the event's result (Blocked or Allowed).


Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Security Activity.


    The Security Activity interface.
  2. Choose a time period of events to view. You can generate a report to document activities for the last hour, the last 24 hours, the previous calendar day (yesterday), the last seven days, and the last month.


    The Time Period interface.
  3. Select which security event types or categories you want to view in the report. By default, all events and categories are selected to display activity for all event types.


    The Event Type interface.
  4. For Response select Allowed, Blocked, or both.

    Note
    If you select Antivirus Disposition is Malicious or Cisco AMP Disposition is Malicious as the Event Type, you cannot select Response > Allowed. Secure Access cannot allow viruses to pass through the system. These will always be blocked.

    AMP Disposition is Malicious as the Event Type, you cannot select Response Allowed. Secure Access cannot allow viruses to pass through the system. These will always be blocked.

    The list of events' details is stacked as cards and sorted by event type (if Group Security Categories is enabled).


    The Sec Act Details interface.
  5. Click an event to view its details. Each security activity card groups an event by destination and lists the details of the event including date and time, destination, identity, and the event's result (Blocked or Allowed).


    The Sec Act Detailed Card interface.

What to do next

Details differ slightly between event type, but all list the destination and identity from which you can click through to the Destination Details and Identity Details.


The Amp Details interface.

Details for AMP and Antivirus events will also include the SHA256 Hash.


The Antivirus Details interface.

Search for Security Activity

To view security activities for a specific source, use the search feature to filter the Activity chart and event details by source.


Prerequisites

  • A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > Security Activity.


    The Security Activity interface.
  2. Type the source's name in the search bar at the top of the page and press Enter. You can only filter by one source at a time.


    The Sec Act Search Identities interface.

To search security activities by more specific fields other than the source, such as domain, URL, or threat type, use the Advanced Search feature.

Procedure

  1. In the search bar, click Advanced.


    The Click Advanced interface.
  2. Enter the fields of your search and then click Apply. You don't have to enter information for each search field, but remember that the more information you can provide, the more successful your search will be.


    The Sec Act Advanced Search interface.