Cisco Secure Access Help

PDF

Cisco Secure Access Help

Report Scheduling

Want to summarize with AI?

Log in

Describes Report Scheduling in Cisco Secure Access. Various reports in Secure Access can be configured so that Secure Access regularly emails you a summary of that report.


Various reports in Secure Access can be configured so that Secure Access regularly emails you a summary of that report. You can configure filters for these reports so that they only contain the information you want. Each emailed report includes an HTML version of the report, a .ZIP file containing a CSV file with the entire data set, and a link to Secure Access and the report. See Schedule a Report.

It is recommended to open the CSV file format of scheduled reports received through email using Numbers (for Mac users) or Excel (for Windows users). This ensures optimal formatting and ease of data analysis.

Reports can be scheduled so that you receive an email daily, weekly, or monthly.

Note
  • You can unsubscribe from a report email through the Unsubscribe link at the bottom of every report email.

  • There is a limit of 100 scheduled reports per organization.

You can schedule the following reports:

  • Remote Access Log —Lists users that have remotely connected to Secure Access and requested access to destinations. The report provides key session details and relevant fields to aid in debugging, troubleshooting, and monitoring remote access activity within your environment.

  • Activity Search—Activity from the identities in your environment over a selected time period. Filterable by identity name, destination, source IP, response, content category, and security category.

  • Network Connectivity Log —Lists events for each tunnel within your Network Tunnel Groups. This log provides key details to help you troubleshoot connectivity issues, monitor tunnel activity, and confirm that traffic is securely transmitted between devices and Secure Access.

  • Total Requests—Total requests for destinations from your organization over the selected time period. Filterable by identity.

  • Activity Volume—Total queries within your organization broken down by security categories and results over the selected time period.

  • Top Destinations—A list of the top traffic-generating identities over the selected time period. Filterable by identity and destination.

  • Top Categories—A list of the top content categories for your organization over the selected time period. Filterable by identity and response.

  • Data Loss Prevention —Lists data violations detected through the DLP Real Time and SaaS API rules.

  • Cloud Malware Report—Provides an overview of malicious files within your environment and details the potential risk and exposure these files present.

  • Events Report—Provides unified, correlated visibility into all security and network events by linking every stage of a traffic flow with a unique Event Correlation ID. This enables end-to-end tracking, streamlined troubleshooting, and comprehensive compliance monitoring across your security environment.

Cisco Secure Access uses SparkPost as the service to deliver email. Some mail filters, either at the local level or even at a transport layer (like an ISP) may block communications from SparkPost as marketing-related spam. If after scheduling your reports you do not receive them, check the spam filter at your mail server gateway. Whether your mail server gateway is hosted locally or in the cloud, it's likely the email was quarantined at that level.

Secure Access sends its reports from scheduled-reports-feedback@opendns.com.

Check Your Spam Folder

Secure Access uses SparkPost as the service to deliver email. Some mail filters, either at the local level or even at a transport layer (for example, an ISP) may block communications from SparkPost as marketing-related spam. If you do not receive your scheduled reports, check the spam filter at your mail server gateway. Whether your mail server gateway is hosted locally or in the cloud, it's likely the email was quarantined at that level.

Unsubscribe From a Report

You can unsubscribe from a scheduled report at any time by clicking the Unsubscribe link at the bottom of the email.


Schedule a Report

When scheduling a report, it's important to select filters so that you receive only the data that you want and that your reports don't exceed 10,000 rows—the limit of an emailed report. As well, you want your scheduled report to be digestible and actionable by recipients. If you choose not to add filters, the report will apply to all traffic types for that report across your entire environment and may contain too much data to be readily read and interpreted by the recipient. With scheduled reports, you select filters for the report before you run the Schedule wizard.

Note
Once scheduled, if you do not receive the report, check the spam filter at your mail server gateway—whether it is hosted locally or hosted in the cloud. It's likely that the email was quarantined at that level.

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports and select the report you want to schedule.

    For a list of schedulable reports, see Report Scheduling.

  2. Select filters for the report and then click Schedule.

    Filters are applied to the report and the Scheduling wizard opens.

    Filters are applied to the report and the Scheduling wizard opens.
  3. Review filters and click Continue .


    Filters are applied to the report and the Scheduling wizard opens. Review filters and click Continue.
  4. Select time parameters to set when and how often you want this report sent to recipients. Click Continue.

    For each time period, you can specify a time and range within that time period. Data is limited to 100,000 rows when exporting to CSV. If your report exceeds 100,000 rows, consider re-running the report with a shorter timeframe or with a more granular filter. It's a good idea to check the last row of your first report, then re-run the report from that time period for the next chunk of data.

    Note
    Delivery schedule defaults to the timezone of the user scheduling the report. If additional recipients need reports delivered at a different time, set up additional scheduled reports with the appropriate delivery schedule.
    Note
    Attempting to schedule a report for a time on the current day, regardless of whether the report is scheduled in the future from the current time on that same day, results in the report being scheduled on the next day at the earliest for weekly and monthly frequencies.

    Report is scheduled in the future from the current time on that same day, results in the report being scheduled on the next day at the earliest for weekly and monthly frequencies.
  5. Give your report a good descriptive name, add email addresses for recipients of this report, and click Save.

    Enter as many recipients as you like separating addresses with commas or semicolons.


    Enter as many recipients as you like separating addresses with commas or semicolons.
  6. Your newly scheduled report is listed at Monitor > Management > Scheduled Reports.

    You can update this schedule at any time. For more information, see Update a Scheduled Report.


Update a Scheduled Report

You can update your scheduled reports at any time. When you update filters for the scheduled report, the Scheduling wizard takes you to the report in question, where you can select filters as necessary and then save the updated schedule.

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > > Management > Scheduled Reports and click a scheduled report.

    The Edit Scheduled Report modal opens and lists filters applied to the report.


    The Scheduled Reports interface.
  2. Review and edit filters, if needed. Click Continue.


    The Save Changes interface.
  3. Update recipients (press Enter to add addresses), the report's delivery schedule, and click Save.


    The Mail Scedule Report interface.

    Your newly updated scheduled report is listed at Monitor > Management > Scheduled Reports.

    Note
    This updated report replaces the current report.

    The Scheduled Reports Updated Schedule interface.