Reports

The following topics describe how to work with reports:

Requirements and prerequisites for reports

Model support

Any.

Supported domains

Any

User roles

  • Admin

  • Maintenance User (risk reports only)

  • Security Analyst

Reports

The system offers two types of reports:

  • Risk reports: Offers high-level summaries of risks found on your network.

  • Standard reports: Provides detailed, customizable reports about all aspects of your system.

Risk reports

A risk report is a portable, high-level summary that

  • presents high-level, easy-to-interpret overviews of risks identified within your organization,

  • includes recommendations for addressing identified security concerns, and

  • enables sharing of risk information with individuals who may not have access to your security system or specialist expertise.

Risk report usage

You can use risk reports to share information about areas of risk and recommendations for addressing these risks with stakeholders who may not be network security experts.

Risk report templates

This topic provides a brief description of various risk report templates.

  • Advanced Malware Risk Report

  • Attacks Risk Report. These are the fields in this report:

    • Total Attacks—The total number of IPS events.

    • Relevant Attacks—The number of IPS events with impact flag equal to 1.

    • Hosts Targeted—The number of unique destination IP addresses from IPS events ​with impact flag equal to 1.

    • Irrelevant Attacks—The percentage of IPS events with impact ​flag not equal to 1.

    • Events Requiring Attention—The percentage of IPS events with impact flag equal to 1.

    • Hosts Connected to CnC Servers—​The total number of unique hosts with the IOC category: "CnC Connected."

  • Network Risk Report

Generate, view, and print risk reports

Templates for standard reports do not apply to risk reports.

Reports pertain to the current domain.

Each risk report generates as an HTML file.

To schedule risk report generation, refer to Schedule reports.

Before you begin

  • Make sure your system is configured to detect the risks that you want to summarize.

  • If you want to email the report and you have not yet configured a Relay Host, you can do so now. For information, refer to Configure a mail relay host and notification address.

Follow these steps to generate, view, and print risk reports:

Procedure


Step 1

Choose Overview > Reporting.

Step 2

Click Report Templates.

Step 3

Click Generate Report for the desired report.

Step 4

Enter information.

  • Information that you enter in the Input Parameters section will appear on the title page of the report. You can leave these fields blank.

Step 5

Click Generate.

Step 6

Click OK.


What to do next

  • To view, download, move, or delete a risk report, refer to Generated reports.

  • You can print to PDF any risk report from most supported browsers. For best results, enable background colors, images, and optionally headers and footers, in the print or print preview settings of your browser. Supported page sizes are A4 and US letter.

Standard reports

A report is a document file formatted in PDF, HTML, or CSV with the content you want to communicate. A report template specifies the data searches and formats for the report and its sections. The system includes a powerful report designer that automates the design of report templates. You can replicate the content of any event view table or dashboard graphic displayed in the web interface.

Report templates and customization

The system provides a flexible reporting system that allows you to quickly and easily generate multi-section reports with the event views or dashboards that appear on your Firewall Management Center. You can also design your own custom reports from scratch.

You can build as many report templates as you need. Each report template defines the individual sections in the report and specifies the database search that creates the report’s content, as well as the presentation format (table, chart, detail view, and so on) and the time frame.

Your template also specifies document attributes, such as the cover page and table of contents and whether the document pages have headers and footers (available only for reports in PDF format). You can export a report template in a single configuration package file and import it for reuse on another Firewall Management Center.

You can include input parameters in a template to expand its usefulness. Input parameters allow you to produce tailored variations of the same report. When you generate a report with input parameters, the generation process prompts you to enter a value for each input parameter.

The values you type constrain the report contents on a one-time basis. For example, you can place an input parameter in the destination IP field of the search that produces an intrusion event report; at report generation time, you can specify a department’s network segment when prompted for the destination IP address. The generated report then contains only information concerning that particular department.

About designing reports

Report templates

A report template is a report configuration tool that

  • enables you to define the content and format for each section of a report,

  • allows you to configure document attributes such as cover page, table of contents, and page headers and footers, and

  • remains available for future reuse until you delete it.

Report template design and format options

Your reports contain one or more information sections. You choose the format (text, table, or chart) for each section individually. The format you select for a section may constrain the data that can be included. For example, you cannot show time-based information in certain tables using a pie chart format. You can change the data criteria or format of a section at any time to obtain optimum presentation.

You can base a report's initial design on a predefined event view, or you can start your design by importing content from any defined dashboard, workflow, or summary. You can also start with an empty template, adding sections and defining their attributes one by one.


Note


In a multidomain deployment, you can view but not edit report templates belonging to ancestor domains. To generate reports from these templates, you must copy them to your current domain.


Report template section fields

The table describes the fields you can use to build sections in a report template. Some fields are available only for specific section types. After you select a section format, the system displays the appropriate fields.

Field Name

Section Types

Definition

Format

n/a

Choose the format of the section data:

Bar chart (bar chart icon): Compares quantities of the selected variables.

Line chart (line chart icon): Shows trends/changes over time of a selected variable. Available only for time-based tables.

Pie chart (pie chart icon): Shows each selected variable as a percentage of the whole. Variables with quantities of zero are dropped from the chart. Very small quantities are clustered into a category labeled Other.

Table view (table view icon): Shows values of attributes for each record. Not available for summary or statistical data.

Detail view (detail view icon): Shows complex object data associated with certain events, such as packets (for intrusion events) and host profiles (for host events). This format is available only for certain event types that involve such objects. Output may degrade performance if large numbers are requested.

Table

All

Choose the table from which the section data is extracted.

Preset

All

Predefined searches. Select an appropriate preset to initialize the search criteria when you define a new search.

Search or Filter

All

For most tables, you can constrain a report using a predefined or saved Search. You can also create a new search by clicking Edit (edit icon).

For the Application Statistics table, you use a user-defined application Filter to constrain a report.

X-Axis

Bar chart

Line chart

Pie chart

Available data for the X-axis of the selected chart.

For line charts, the X-axis value is always Time. For bar and pie charts, you cannot select Time as the X-axis value.

Y-Axis

Bar chart

Line chart

Pie chart

Available data for the Y-axis of the selected chart.

Section Description

All

Descriptive text that precedes the search data in the section.

Enter a combination of text and input parameters. The default for a new section is $<Time Window> and $<Constraints>.

Time Window

All

The time window for the data that appears in the section.

If the section searches time-based tables, you can select the check box to inherit the report's global time window. Alternatively, you can set a specific time window for the section.

Data Source

All

If you used the wizard to configure remote (external) data storage using Security Analytics and Logging (On Premises), you can choose the data source to use for connection and Security Intelligence events.

Options are:

  • Auto: Show data stored on the Firewall Management Center if available. If data on the Firewall Management Center is not available for the entire selected time window, show only remotely stored data.

  • Local: Show only data that is stored on the Firewall Management Center, regardless of the time window selected.

    Choose this option to include data that is not available on the remote volume, such as events generated from devices that are not configured to send events to the remote volume.

  • Extended: Show only data that is stored on the remote volume.

Maximum Results

Table view

Detail view

The maximum number of matching records to include.

You can include fewer records in a PDF report than in a CSV or HTML report. The web interface uses warning and error icons to indicate when the number is too large. Hover your pointer over the icon to see the limits.

Results

Bar chart

Pie chart

Choose either Top or Bottom and enter the number of matching records you want to use to build the chart.

Color

Bar chart

Line chart

Colors for graphed data in the section.

Report templates

A report template is a framework for organizing report sections that

  • allows each section to be independently built from its own database query,

  • supports creation through several methods, such as starting from an existing template, importing dashboards or workflows, or basing on an event view, and

  • provides features for customizing the format and content of each section.

Report template creation methods

You can build a new report template by creating a new template, using an existing template, basing a template off an event view, or importing a dashboard or workflow.

Report template creation methods include:

  • New template creation: Create an entirely new template by generating the framework and then designing individual template sections

  • Existing template copying: Copy an existing template and edit its attributes to create a new report template

  • Event view-based creation: Create a report template from an event view and modify it by adding, modifying, or deleting sections

  • Import-based creation: Import dashboards, workflows, and statistics summaries to quickly create reports with sections for each widget graphic or event view

If you do not want to copy an existing report template, you can create an entirely new template. The first step in creating a template is to generate the framework that allows you to add and format the sections. Then, in the order you prefer, you design the individual template sections and set attributes for the report document.

Each template section consists of a dataset generated by a search or filter, and has a format specification (table, pie chart, and so on) that determines the mode of presentation. You further determine section content by selecting the fields in the data records you want to include in the output, as well as the time frame and number of records to show.


Note


Use the section preview utility to check the column selection and output characteristics such as pie chart colors. It is not a reliable indicator of the correctness of your configured search.


The report you generate from the template has several document attributes that span all sections and control features, such as the cover page, headers and footers, page numbering, and so on.

Note that if you selected CSV as your document format, you have no document attributes to set.

If you identify a good model among your existing templates, you can copy the template and edit its attributes to create a new report template. Cisco also provides a set of predefined report templates, visible on the Reports Tab in the list of templates.

From an event view, you can create a report template and modify it to meet your needs. You can add additional sections, modify automatically included sections, and delete sections.

You can quickly create a new report by importing dashboards, workflows, and statistics summaries. The import creates a section for each widget graphic in your dashboard and each event view in your workflow. You can delete any unnecessary sections to focus on the most important information.

Create a custom report template

Custom report templates allow you to define the structure, content, and format of reports. You can configure sections, add input parameters, and set attributes for different output formats.

Procedure

Step 1

Choose Overview > Reporting.

Step 2

Click Report Templates.

Step 3

Click Create Report Template.

Step 4

Enter a name for your new template in the Report Title field.

Step 5

To add an input parameter to the report title, place your cursor in the title where the parameter value should appear, then click insert Input Parameter (input parameter icon).

Step 6

Use the set of add under the Report Sections title bar to insert sections as necessary.

Step 7

Configure section content as described in Report templates.

Tip

 

You can click Preview at the bottom of the section window to view the column layout or graphic format you chose.

Step 8

Click Advanced to set attributes for PDF and HTML reports as described in Document attributes in report templates.

Step 9

Click Save.

If you see an error, look for a yellow triangle beside the results value in each section. If you see any such triangles, do one of these:

  • For each field that displays a yellow triangle, mouse over the triangle and reduce the number of results to the number indicated.

  • Click Generate and include an output format other than PDF.


Create a report template from an existing template

Use this procedure when you need a new report template that is similar to an existing one, saving time by starting with a pre-configured template rather than creating one from scratch.

Procedure

Step 1

Choose Overview > Reporting.

Step 2

Click Report Templates.

Step 3

Click Copy (copy icon) next to the report template you want to copy.

Step 4

In the Report Title field, enter a name.

Step 5

Make changes to the template as needed.

Step 6

Click Save.


Create a report template from an event view

This task guides you through creating a report template based on selected events in an event view. You can customize report sections and layout, enhancing reporting flexibility.

Procedure

Step 1

Populate an event view with the events you want in the report:

  • Use an event search to define the events you want to view.
  • Drill down through a workflow until you have the appropriate events in your event view.

Step 2

From the event view page, click Create Report.

The Report Sections page displays a section for each view in the captured workflow.

Step 3

Optionally, enter a new name in the Report Title field and click Save.

Step 4

You can:

  • Add a cover page, table of contents, starting page number, or header and footer text — Click Advanced settings.
  • Add page breaks — Click Add Page Break (add page break icon), and drag the new page break object from the template bottom to the front of the section that should start the new page.
  • Add text sections — Click Add Text Section (add text section icon), and drag the new text section from the template bottom to the place where you want it to appear in the report template.
  • Change the title of a section — Click the section title in the title bar, enter the section title, and click OK.
  • Configure the report sections — Adjust the field settings in each section.

    Tip

     

    To view the current column layout or chart formatting for a section, click the section's Preview link.

  • Exclude template sections from the report — Click Delete (delete icon) in the section's title bar, and confirm the deletion.

    Note

     

    The last report section in some workflows contains detail views that show packets, host profiles, or vulnerabilities, depending on the workflow. Retrieving large numbers of events with these detail views when generating your report may affect performance of the Firewall Management Center.

Step 5

Click Save.


Create a report template by importing a dashboard or workflow

Use this task when you want to create standardized, reusable report templates by pulling in content from dashboards, workflows, or summaries. This feature lets you import widgets or event views as report sections and customize them.

Procedure

Step 1

Identify the dashboard, workflow, or summary you want to replicate in your report.

Step 2

Choose Overview > Reporting, and click Report Templates.

Step 3

Click Create Report Template.

Step 4

Enter a name for your new report template in the Report Title field, and click Save.

Step 5

Click Import Section (import section icon).

You can choose any of the data sources described in Data source options in the Import Report Sections window.

Step 6

Choose a dashboard, workflow, or summary from the drop-down menus.

Step 7

For the data sources you want to add, click Import.

For dashboards, each widget graphic will have its own section; for workflows, each event view will have its own section.

Step 8

Make changes to the content of your sections as needed.

Note

 

The last report section in some workflows contains detail views that show packets, host profiles, or vulnerabilities, depending on the workflow. Retrieving large numbers of events with these detail views when generating your report may affect performance of the Firewall Management Center.

Step 9

Click Save.


Data source options in the Import Report Sections window

The Import Report Sections window provides several data source options that enable you to import specific content into your reports.

The table summarizes each option and the type of data it imports.

Table 1. Data source options on import report sections window

Select this option...

To import...

Import Dashboard

any custom analysis widget on the selected dashboard.

Import Workflow

any predefined or custom workflow.

Selections have the format:
Table - Workflow name 

For example, Connection Events - Traffic by Port imports the views in the Traffic by Port workflow generated from the Connection Events table.

Import Summary Sections

any of these generic summaries:

  • Intrusion Detailed Summary

  • Intrusion Short Summary

  • Discovery Detailed Summary

  • Discovery Short Summary

Report templates

Report template configuration is a customization capability that

  • enables modification of report section attributes to tailor content and presentation,

  • queries database tables to generate content for each section, and

  • allows users to define time windows, searches, filters, and data fields displayed.

Report template configuration capabilities

Each section in a report template queries a database table to generate content for that section. Changing the section's data format uses the same data query, but modifies the fields that appear in the section according to the analytical purpose of the format type. For example, the table view of intrusion events populates the section with a large number of data fields per event record, while a pie chart section shows the portion of all matching records that each selected attribute represents, with no details about individual events.

Bar chart sections compare the total counts of matching records that have specific attributes. Line charts summarize changes in the matching records over time with respect to a single attribute. Line charts are available only for data that is time-based, not for information about hosts, users, third-party vulnerabilities, and so on.

The search or filter in a report section specifies the database query on which the section content is based. For most tables, you can constrain a report using a predefined or saved search, or you can create a new search on the fly:

  • Predefined searches serve as examples for searching certain event tables and can provide quick access to important information about your network that you may want to include in reports.

  • Saved event searches include all public event searches that you or others have created, plus all your saved private event searches.

  • Saved searches for the current report template are accessible only in the report template itself. The search names of saved report template searches end with the string "Custom Search." Users create these searches while designing reports.

For the Application Statistics table, you use a user-defined application filter to constrain a report.

If you include table data in a section, you can choose which fields in the data record to show. All fields in the table are available for inclusion or exclusion. You select fields that accomplish the purpose of the report, then order and sort them accordingly.

You can add text sections to your templates to provide custom text, such as an introduction, for the whole report or for individual sections.

You can add page breaks before or after any section in the template. This feature is particularly helpful for multi-section reports with text pages that introduce the various sections.

A report template's time window defines the template's reporting period.


Note


Security Analysts can edit only report templates they created. In multidomain deployments, you cannot edit report templates from ancestor domains, but you can copy them to create descendant versions.


Configure table and data format in a report template section

Report template sections require configuration of both the data source table and the output format to properly display reporting information. The available output formats depend on the selected table type.

Procedure

Step 1

Choose Overview > Reporting, click the Report Templates tab, and then click Create Report Template.

Step 2

In the report template section, use the Table drop-down menu to choose the table to query.

The Format field represents each of the output formats available for the table you chose.

Step 3

Choose the applicable output format for the section.

Step 4

To change the search constraints, click Edit (edit icon) next to the Section description field or Filter field.

Step 5

For graphic output formats (pie chart, bar chart, and so on), adjust the X-Axis and Y-Axis parameters using the drop-down menus.

When you choose a value for the X-axis, only compatible values appear in the Y-axis drop-down menu, and vice versa.

Step 6

For table output, choose the columns, order of appearance, and sort order in your output.

Step 7

Click Save.


Specify search or filter criteria for a report template

Use this task when creating or customizing a report template to ensure the resulting report displays only the data you need.

Procedure

Step 1

In the report template section, choose the database table to query from the Table drop-down menu:

  • For most tables, the Search drop-down list appears.
  • For the Application Statistics table, the Filter drop-down list appears.

Step 2

Choose the search or filter you want to use to constrain the report.

You can view the search criteria or create a new search by clicking Edit (edit icon).


Modify fields in a report table

Use this task to tailor report tables to show the information that matters most for your analysis or audience.

Procedure

Step 1

For table-format report sections, click the Edit (edit icon) icon next to the Fields parameter.

Step 2

In the table field selector dialog box that is displayed, you can do the following:

  • Click the column name or the Add add icon icon next to a column to add it to the report. The added column names are populated in the Selected Column pane.

  • Click the Remove remove icon icon next to a column to remove the column from the report.

  • Drag and drop the columns in the Selected Column pane to rearrange them, as required.

  • Choose a Sort direction and set a Sort priority for a column to modify the order in which the data is sorted.

Step 3

Click OK.


Add a text section to a report template

Text sections allow you to include introductions or explanatory content in your report templates. These sections support varied font styles, input parameters that update dynamically, and imported images for enhanced presentation.


Tip


Text sections are useful for introductions to your report or your report sections.


Procedure

Step 1

In the report template editor, click Add Text Section (add text section icon).

Step 2

Drag the new text section to its intended position in the report template.

Step 3

If you want to position the text section first or last on a page, add page breaks before or after the text section.

Step 4

If you want to change the text section's generic name, click section's name in the title bar, and enter a new name.

Step 5

Add formatted text and images to the body of the text section.

You can include input parameters that dynamically update when you generate the report.

Step 6

Click Save.


Add a page break to a report template

Use page breaks in report templates to visually separate sections, making reports more readable and easier to review.

Procedure

Step 1

In the report template editor, click Add Page Break (add page break icon).

A page break appears at the bottom of the template.

Step 2

Drag the page break to its intended location, before or after a section.

Step 3

Click Save.


Global time windows in report template sections

A global time window is a report template feature that

  • applies to report templates with time-based data such as intrusion or discovery events,

  • provides default time settings that time-based sections inherit when created, and

  • can be modified to change local time windows for sections configured to inherit the global setting.

Time window inheritance behavior

Changing the global time window changes the local time window for the sections that are configured to inherit the global time window. You can disable time window inheritance for an individual section by clearing its Inherit Time Window check box. You can then edit the local time window.


Note


Global time window inheritance applies only to report sections with data from time-based tables, such as intrusion events and discovery events. For sections that report on network assets (hosts and devices) and related information (such as vulnerabilities), you must set each time window individually.


Set the global time window for a report template and its sections

A report template can contain multiple sections, each with its own time range. For instance, you might set the first section as a monthly summary and configure other sections to provide weekly details. This process enables you to modify the global time window for the template while also allowing section-level adjustments.

Procedure

Step 1

In the report template editor, click Generate.

Step 2

To modify the global time window, click Time Window (time window icon).

Step 3

Modify time settings in Events Time Window.

Step 4

Click Apply.

Step 5

Click Generate to generate the report and Yes to confirm.


Set the local time window for report template sections

Adjusting the time window allows you to focus each section on a relevant date range, especially for statistical data that supports only sliding windows.

Procedure

Step 1

On the Report Sections page of a template, clear the Inherit Time Window check box for the section if it is present.

Step 2

To change the section's local time window, click Time Window (time window icon).

Note

 

Sections with data from statistics tables can have only sliding time windows.

Step 3

Click Apply on the Events Time Window.

Step 4

Click Save.


Rename a report template section

Use this task when reorganizing report templates or when a section name no longer fits its content.

Procedure

Step 1

In the report template editor, click the current section name in the section header.

Step 2

Enter a new name for the section.

Step 3

Click OK.


Preview a report template section

The preview function shows the field layout and sort order for table views and important legibility characteristics of graphics, such as pie chart colors.

Procedure

Step 1

At any time while editing a report template section, click Preview for the section.

Step 2

Close the preview by clicking OK.


Report template searches

A report template search is a configuration feature that

  • defines the criteria for retrieving data to populate sections of a report,

  • enables the inclusion of both predefined and custom searches within a report template, and

  • utilizes a search editor to manage, view, and customize available searches.

Search editor capabilities

The system provides a search editor, allowing you to view existing searches in report templates and to define new custom searches tailored to your reporting needs.

Search in report template sections

Use this task when you need to filter or locate specific data in a report template section, either by customizing search criteria or basing your search on predefined queries.

Procedure

Step 1

From the relevant section in the report template, click Edit (edit icon) next to the Search field.

Step 2

If you want to base a custom search on a predefined search, you must choose a predefined search from the Saved Searches drop-down list.

This list includes all available predefined searches for this table, including system-wide and report-specific predefined searches.

Step 3

Edit the search criteria in the appropriate fields.

For certain fields, your constraints can include the same operators (<, <>, and so on) as event searches. If you enter multiple criteria, the search returns only the records that match all the criteria.

Step 4

If you want to insert an input parameter from the drop-down menu instead of entering a constraint value, you must click Input Parameter (input parameter icon).

Note

 

When you edit the constraints of a reporting search, the system saves your edited search under the following name: section custom search, where section is the name in the section title bar followed by the string custom search. To have meaningful names for your saved custom searches, be sure you change the section name before you save the edited search. You cannot rename a saved reporting search.

Step 5

Click OK.


Input parameters

An input parameter is a report template attribute that

  • allows the report to collect dynamic values from the user during generation,

  • supports both predefined (system-resolved) and user-defined (customizable) constraints, and

  • enables customization of report sections and fields such as search filters, email text, and file names.

Input parameter types

There are two types of input parameters:

  • Predefined input parameters: These are resolved by internal system functions or configuration information. For example, at report generation time, the system replaces the $<Time> parameter with the current date and time.

  • User-defined input parameters: These supply constraints in report section searches. Constraining a search with an input parameter instructs the system to collect a value at generation time from the person who requests the report. In this way, you can dynamically tailor a report at generation time to show a particular subset of data without changing the template. For example, you can provide an input parameter for the Destination IP field of a report section's search. Then, when you generate the report, you can enter the IP network segment for a particular department to get data for that department only.

    You can also define string-type input parameters to add dynamic text in certain fields of your report, such as in emails (subject or body), report file names, and text sections. You can personalize reports for different departments, with customized report file names, email addresses, and email messages, using the same template for all.

Report template predefined input parameters

This reference provides information about predefined input parameters that can be inserted into report templates to include dynamic content such as logos, dates, system information, and other contextual data.

Table 2. Predefined input parameters

Insert this parameter...

...to include this information in your template:

$<Logo>

The selected uploaded logo

$<Report Title>

The report title

$<Time>

The date and time of day the report ran, with one-second granularity

$<Month>

The current month

$<Year>

The current year

$<System Name>

The name of the Firewall Management Center

$<Model Number>

The model number of the Firewall Management Center

$<Time Window>

The time window currently applied to the report section

$<Constraints>

The search constraints currently applied to the report section

Table 3. Predefined input parameter usage

Parameter

Report Template Cover Page

Report Template Report Title

Report Template Section Description

Report Template Text Section

Generate Report File Name

Generate Report Email Subject, Body

$<Logo>

yes

no

no

no

no

no

$<Report Title>

yes

no

yes

yes

yes

yes

$<Time>

yes

yes

yes

yes

yes

yes

$<Month>

yes

yes

yes

yes

yes

yes

$<Year>

yes

yes

yes

yes

yes

yes

$<System Name>

yes

yes

yes

yes

yes

yes

$<Model Number>

yes

yes

yes

yes

yes

yes

$<Time Window>

no

no

yes

no

no

no

$<Constraints>

no

no

yes

no

no

no

User-defined input parameters

You use input parameters to expand the usefulness of your searches. The input parameter instructs the system to collect a value at generation time from the person who requests the report. In this way, you can dynamically constrain a report at generation time to show a particular subset of data without changing the search. For example, you can provide an input parameter for the Destination IP field of a report section that drills down on security events at a department level. When you generate the report, you can type the IP network segment for a particular department to get data for that department only.

An input parameter's type determines the search fields where you can use it. You can use a given type only in appropriate fields. For example, a user parameter you define as a string type is available for insertion in text fields but not in fields that take an IP address.

Each input parameter you define has a name and a type.

Table 4. User-Defined input parameter types

Use this parameter type...

With fields with this data...

Network/IP

any IP address or network segment in CIDR format

Application

name of an application protocol, client application, or web application

Event Message

any event view message

Device

a Firewall Management Center or managed device

Username

user identification such as initiator user and responder user

Number (VLAN ID, Snort ID, Vuln ID)

any VLAN ID, Snort ID, or vulnerability ID

String

text fields such as application or OS version, notes, or descriptions

Create user-defined input parameters

This task allows you to define additional input parameters in report templates, helping you capture and filter data based on your requirements.

Procedure

Step 1

In the report template editor, click Advanced.

Step 2

Click Add Input Parameter (add input parameter icon).

Step 3

Enter the parameter Name.

Step 4

Choose a value from the Type drop-down list.

Step 5

Click OK to add the parameter.

Step 6

Click OK to return to the editor.


Edit user-defined input parameters

Edit user-defined input parameters to customize report template functionality and ensure parameters meet specific reporting requirements.

The Input Parameters section of the report template lists all available user-defined parameters for the template.

Procedure

Step 1

In the report template editor, click Advanced.

Step 2

Click Edit (edit icon) next to the parameter you want to modify.

Step 3

Enter a new Name.

Step 4

Use the Type drop-down list to change the parameter type.

Step 5

Click OK to save your changes.

Step 6

If you want to delete an input parameter, click Delete (delete icon) next to the input parameter and confirm.

Step 7

Click OK to return to the report template editor.


Constrain a search with user-defined input parameters

User-defined input parameters allow you to tailor searches so that only fields matching the parameter type are available for selection. For example, an input parameter of type Network/IP is available only for fields that accept IP addresses or network segments in CIDR format.

Procedure

Step 1

In the report template editor, click Edit (edit icon) next to the Search field within the section.

Fields that can take an input parameter are marked with Input Parameter (input parameter icon).

Step 2

Click Input Parameter (input parameter icon) next to the field, then choose the input parameter from the drop-down menu.

User-defined input parameters are marked with (The diagram illustrates how user-defined input parameters constrain a search, highlighting fields that accept input parameters and indicating the effect of the selected parameter on search results.).

Step 3

Click OK.


Document attributes in report templates

Before you generate your report, you can set document attributes that affect the report's appearance. These attributes include the optional cover page and table of contents. Support for some attributes depends on the selected report format: PDF, HTML, or CSV.

Table 5. Document attribute support

Attribute

PDF Support?

HTML Support?

CSV Support?

Cover page

yes, with optional logo and custom appearance

yes, with optional logo and custom appearance

no

Table of contents

yes

yes

no

Page headers and footers

yes, with optional text or logo in any field

no

no

Custom starting page number

yes

no

no

Option to suppress numbering of first page

yes

no

no

Edit document attributes in a report template

Use the Advanced settings in the report template editor to modify various document attributes that control the overall layout and presentation of your reports.

Procedure

Step 1

In the report template editor, click Advanced.

Step 2

You have the following choices:

  • Add cover page: To add a cover page, check the Include Cover Page check box.
  • Customize cover page: To edit the cover page design, refer to Customize a cover page.
  • Add table of contents: To add a table of contents, check the Include Table of Contents check box.
  • Manage logos: To manage the logo image associated with the template, refer to Manage report template logos.
  • Configure header and footer:To specify elements for the header and footer of the template, use the drop-down lists in the Header and Footer fields.
  • Set first page number: To specify the page number of the report's first page, enter a Page Number Start value.
  • Show first page number:To show the page number on the report's first page, check the Number First Page? check box. If you choose this option, the cover page is not numbered.

Step 3

Click OK to save your changes.


Customize a cover page

You can modify a report template’s cover page to include multiple font sizes and styles (such as bold or italic), custom images, and input parameters. This creates a visually distinctive and informative report for stakeholders.

Procedure

Step 1

In the report template editor, click Advanced.

Step 2

Click Edit (edit icon) next to Cover Page Design.

Step 3

Edit the cover page design within the rich text editor.

Step 4

Click OK.


Manage report template logos

You can store multiple logos on the Firewall Management Center and associate them with different report templates. You set the logo association when you design the template. If you export the template, the export package contains the logo.

When you upload a logo to the Firewall Management Center, it is available for:

  • all report templates on the Firewall Management Center, or

  • in a multidomain deployment, all report templates in your current domain

Logo images can be in GIF, JPG, or PNG format.

You can change the logo in a report to any JPG image uploaded to your Firewall Management Center. For example, if you reuse a template, you can associate a logo for a different organization with the report.

You can delete any uploaded logos. Deleting a logo removes it from all templates where it is used. The deletion cannot be undone. Note that you cannot delete the predefined Cisco logo.

Procedure

Step 1

In the report template editor, click Advanced.

The logo currently associated with the template appears under Logo in General Settings.

Step 2

Click Edit (edit icon) next to the logo.

Step 3

You have the following choices:


Add a new logo

Adding a custom logo personalizes your report template and helps maintain brand consistency across your organization's security reports.

You can customize report templates by adding your organization's logo. This logo will appear on all reports generated using this template.

Before you begin

Follow these steps to add a new logo:

Procedure

Step 1

In the report template editor, click Advanced.

Step 2

Click Edit (edit icon) next to the Logo field.

Step 3

Click Upload Logo.

Step 4

Click Browse, browse to the file's location, and click Open.

Step 5

Click Upload.

Step 6

If you want to associate the new logo with the current template, choose it, and click OK.


The new logo is uploaded and can be associated with the current report template. When you generate reports using this template, the custom logo will appear on the reports.

Change the logo for a report template

Changing the logo in a report template allows you to personalize reports and align them with your organization's branding.

Procedure

Step 1

In the report template editor, click Advanced.

Step 2

Click Edit (edit icon) next to the Logo field.

Step 3

From the Select Logo dialog, choose the logo to associate with the report template.

Step 4

Click OK.


Delete a logo

Use this task when you need to update a report template by deleting a logo that is no longer appropriate or required.

Procedure

Step 1

In the report template editor, click Advanced.

Step 2

Click Edit (edit icon) next to the Logo field.

Step 3

From the Select Logo dialog, choose the logo you want to delete.

Step 4

Click Delete Logo.

Step 5

Click OK.


Manage report templates

In a multidomain deployment, the system displays report templates created in the current domain, which you can edit. It also displays report templates created in ancestor domains, which you cannot edit. To view and edit report templates in a lower domain, switch to that domain. The system displays reports created in the current domain only.

You must be an Admin user to perform this task.

Procedure

Step 1

Choose Overview > Reporting.

Step 2

Click Report Templates.

Step 3

Choose one of the following actions:

  • Delete: Next to the template you want to delete, click Delete (delete icon) and confirm.

    You cannot delete system-provided report templates. Security Analysts can delete only report templates they created. In a multidomain deployment, you can delete report templates belonging to the current domain only.

  • Edit: To edit report templates; refer to Editing report templates.
  • Export: To export report templates, refer to Export report templates.

    Tip

     

    You can also export report templates using the standard configuration export process; see Export Configurations.

  • Import: To import report templates, see Import Configurations.

Editing report templates

In a multidomain deployment, the system displays report templates created in the current domain, which you can edit. It also displays report templates created in ancestor domains, which you cannot edit. To view and edit report templates in a lower domain, switch to that domain.

Procedure

Step 1

Choose Overview > Reporting.

Step 2

Click Report Templates.

Step 3

Click Edit (edit icon) for the template you want to edit.

If View (View button) appears instead, the configuration belongs to an ancestor domain, or you do not have permission to modify the configuration.

Step 4

You have the following choices:


Export report templates
Admin users can export report templates from Firewall Management Center. This feature is useful for sharing templates, migrating them between systems, or creating backups.

Before you begin

You must be an Admin user to perform this task.

Procedure

Step 1

Choose Overview > Reporting.

Step 2

Choose Report Templates.

Step 3

For the template you want to export, click the Export icon.


About generating reports

Generate reports

After you create and customize your report template, you are ready to generate the report. The generation process lets you select the report's format (HTML, PDF, or CSV). You can also adjust the report's global time window, which applies a consistent time frame to all sections except those you exempt.

For PDF reports:

  • File names using Unicode (UTF-8) characters are not supported.

  • Any report sections that include special Unicode file names (such as those appearing in file or malware events) display these file names in transliterated form.

  • The configured number of results configured in each report section must be within certain limits. To view those limits, mouse over any yellow triangles you see in your report template.

If the report template includes user input parameters in its search specification, the generation process prompts you to enter values, which tailor this run of the report to a subset of the data.

If you have a DNS server configured and IP address resolution enabled, reports contain host names if resolution was successful.

In a multidomain deployment, when you generate a report in an ancestor domain, it can include results from all descendant domains. To generate a report for a specific leaf domain, switch to that domain.

Procedure

Step 1

Choose Overview > Reporting.

Step 2

Click Report Templates.

Step 3

Click Report (Report icon) next to the template you want to use to generate a report.

If the controls are dimmed, the configuration belongs to an ancestor domain, or you do not have permission to modify the configuration.

Tip

 

To generate a report from an ancestor's template, copy the template into the current domain.

Step 4

Optionally, configure the report name:

  • Enter a new File Name. If you do not enter a new name, the system uses the name specified in the report template.
  • Use Input Parameter (input parameter icon) to add one or more input parameters to the file name.

Step 5

Choose the output format for the report by clicking: HTML, PDF, or CSV.

If the PDF option is dimmed, the configured number of results in one or more report sections may be too high. For specific limits, look for yellow triangles in the report template and hover your mouse over any that you find.

Step 6

If you want to change the global time window, click Time Window (time window icon).

Note

 

Setting the global time window affects the content of individual report sections only if they are configured to inherit the global setting.

Step 7

Enter values for any fields that appear in the Input Parameters section.

Tip

 

You can ignore user parameters by typing the * wildcard character in the field. This eliminates the user parameter's constraint on the search.

Note

 

The system builds a separate network map for each leaf domain. In a multidomain deployment, using literal IP addresses or VLAN tags to constrain report results can have unexpected results.

Step 8

If you enabled an email relay host in the Firewall Management Center configuration, click Email to automate email delivery of the report when it generates.

Step 9

Click Generate and confirm when prompted.

Clicking Generate saves Generate settings with the report template.

If you click Close, your selections are saved only for the duration of your session.

You have the following choices:

  • Click the report link to display the report in a new window.
  • Click OK to return to the report template editor.

Report generation options

A report generation option is a report management feature that

  • enables scheduling of report creation at various intervals,

  • allows distribution of generated reports by email or remote storage, and

  • requires configuration of templates, mail relay, or storage to automate delivery.

Available report generation options

You can configure these report generation options:

  • Schedule generation of future reports, either once or recurring. For more information, refer to Schedule reports. You can customize the schedule on a full range of time frames such as daily, weekly, monthly, and so on.

  • Distribute email reports using the scheduler. You must configure your report template and a mail relay host before scheduling the task.

  • Automatically send the report as an email attachment to a list of recipients when you generate a report. You must have a properly configured mail relay host to deliver a report by email.

  • Save newly generated report files to your configured remote storage location. To use remote storage, you must first configure a remote storage location.


    Note


    If you store remotely and then switch back to local storage, the reports in remote storage do not appear on the Reports tab list. Similarly, if you switch from one remote storage location to another, the reports in the previous location do not appear in the list.

Distribute reports by email when generated

Use this procedure when you need to configure a report template to automatically send the generated report via email to specific recipients. This is useful for regular reporting schedules or when you want to ensure timely delivery of critical security reports.

Procedure

Step 1

Choose Overview > Reporting.

Step 2

Click Report Templates.

Step 3

Click Report (Report icon) next to the template you want to use to generate a report.

If the controls are dimmed, the configuration belongs to an ancestor domain, or you do not have permission to modify the configuration.

Tip

 

To generate a report from an ancestor's template, copy the template into the current domain.

Step 4

Expand the Email section of the window.

Step 5

In the Email Options field, choose Send Email.

Step 6

In the Recipient List, CC, and BCC fields, enter recipients' email addresses in comma-separated lists.

Step 7

In the Subject field, enter an email subject.

Tip

 

You can provide input parameters in the Subject field and the message body to dynamically generate information in the email, such as a timestamp or the name of the Firewall Management Center.

Step 8

Enter a cover letter in the email body as necessary.

Step 9

Click OK and confirm.


Scheduled future reports

A scheduled future report is an automated reporting feature that

  • generates reports at specified intervals,

  • operates without manual intervention, and

  • provides regular report delivery for consistent monitoring.

Use scheduled reports when you need regular, automated report generation without manual intervention. For more information, refer to Schedule reports.

Generated reports

A generated report is a record that

  • provides access to previously-created report content,

  • is accessible through the Reports tab page interface, and

  • enables users to access, analyze, and export information as needed.

Report access location

Access and work with previously-generated reports on the Reports tab.

View reports

The Reports lists all previously generated reports, with report name, date and time of generation, generating user, and whether the report is stored locally or remotely. A status column indicates whether the report is already generated, is in the generation queue (for example, for scheduled tasks), or failed to generate (for example, due to lack of disk space).

Note that users with Administrator access can view all reports; other users can view only the reports they generated.

In a multidomain deployment, you can view reports generated in the current domain only.

The Reports page shows all locally stored reports. It shows remotely stored reports as well, if remote storage is currently configured. The Location column data for remotely-stored reports is Remote.


Note


If you store remotely and then switch back to local storage, the reports in remote storage do not appear on the Reports tab list. Similarly, if you switch from one remote storage location to another, the reports in the previous location do not appear in the list.

Procedure


Step 1

Choose Overview > Reporting.

Step 2

Click Reports.

Step 3

Click the report you want to view.


Download reports

You can download any report file to your local computer. From there, you can email it or distribute it electronically by other available means.

In a multidomain deployment, you can download reports generated in the current domain only.

Procedure


Step 1

Choose Overview > Reporting.

Step 2

Click Reports.

Step 3

Check the check boxes next to the reports you want to download, then click Download.

Tip

 

Click the check box at the top left of the page to download all reports on the page. If you have multiple pages of reports, a second check box appears that you can click to download all reports on all pages.

Step 4

Follow your browser's prompts to download the reports. If you chose multiple reports, they are downloaded in a single .zip file.


Store reports remotely

The location of your currently configured report storage appears at the bottom of the Reports page (Overview > Reporting) with disk usage for local, NFS, and SMB storage. If you access remote storage using SSH, disk usage data is not available.


Note


If you store remotely and then switch back to local storage, the reports in remote storage do not appear on the Reports tab list. Similarly, if you switch from one remote storage location to another, the reports in the previous location do not appear in the list.

Before you begin

Configure a remote storage location as described in Remote storage devices.

Follow these steps to store reports remotely:

Procedure


Step 1

Choose Overview > Reporting.

Step 2

Choose Reports.

Step 3

Check the Enable Remote Storage of Reports check box at the bottom of the page.


What to do next

Move reports from local storage to remote storage; refer to Moving reports to remote storage.

Moving reports to remote storage

Use this task to move reports stored locally to a configured remote storage location for better accessibility and to free up local space. You can move reports in batches or individually.


Note


If you store remotely and then switch back to local storage, the reports in remote storage do not appear on the Reports tab list. Similarly, if you switch from one remote storage location to another, the reports in the previous location do not appear in the list.

Before you begin

Configure a remote storage location as described in Remote storage devices.

Note


If you store remotely and then switch back to local storage, the reports in remote storage do not appear on the Reports tab list. Similarly, if you switch from one remote storage location to another, the reports in the previous location do not appear in the list.

Follow these steps to move reports to remote storage:

Procedure


Step 1

Choose Overview > Reporting.

Step 2

Choose Reports.

Step 3

Choose the check boxes next to the reports you want to move, then click Move.

Tip

 

Check the check box at the top left of the page to move all reports on the page. If you have multiple pages of reports, a second check box appears that you can check to move all reports on all pages.

Step 4

Confirm that you want to move the reports.


Delete reports

You can delete your report files at any time. The procedure completely removes the files, and no recovery is possible. Although you still have the report template that generated the report, it may be difficult to regenerate a particular report file if the time window was expanding or sliding. Regeneration may also be difficult if your template uses input parameters.

In a multidomain deployment, you can delete reports generated in the current domain only.

Procedure


Step 1

Choose Overview > Reporting.

Step 2

Click Reports.

Step 3

You have the following choices:

  • Delete selected: Check the check boxes next to the reports you want to delete, then click Delete.
  • Delete all: Check the check box at the top left of the page to delete all reports on the page. If you have multiple pages of reports, a second check box appears that you can check to delete all reports on all pages.

Step 4

Confirm the deletion.


Report template feature history

This reference documents the historical development and changes to reporting functionality, including feature enhancements, version compatibility, and implementation details.

Feature

Minimum Firewall Management Center

Minimum Firewall Threat Defense

Details

Usability improvements for report template creation

7.6.0

Any

Improved user interface for setting the search fields that appear in table-format sections of the report. This new user interface includes buttons for adding and deleting report fields, a drag-and-drop function for rearranging the fields, and simplified sorting options.

New/modified screens: Overview > Reporting > Report Templates > Create Report Template, click the Add Table View icon, and then click the edit icon next to Fields.

Choose a data source for connection events in report templates

7.0

Any

If you use the wizard to configure remote data storage using Security Analytics and Logging (On Premises), you can choose to include data stored on that volume in reports.

Modified page: Report template

Changes to Vulnerabilities reports

6.7

Any

Report output has been adjusted for the lack of availability of Bugtraq data.