Scheduled detection reports

Last updated on:

Overview

The Scheduled Detection Reports feature in the Manage Rules module provides a way to generate and export periodic reports for rule-based detections. Administrators can create new schedules, define frequency, select rules, configure export formats, and set notifications. These reports provide detailed visibility into detections over a specified time range, helping with trend analysis, compliance requirements, and continuous monitoring.

Scheduled detection reports (via the Manage Rules module)

Provides logs detected for a particular rule over a specified period of time.

  1. You can access these reports by clicking on the Scheduled Detection Reports option in the Manage Rules module as highlighted below.
    Scheduled reports in the manage rules module
    Image 1: Scheduled reports in the manage rules module
  2. You will be taken to the Scheduled Reports module.

To create a new schedule for the report(s)

  1. Click on the Create New Schedule button as highlighted below.
    Create scheduled reports in the manage rules module
    Image 2: Create scheduled reports in the manage rules module
  2. You will be taken to the Create Schedule module.
    Create scheduled reports in the manage rules module
    Image 3: Create scheduled reports in the manage rules module
    • Schedule Details
      • Schedule Name: Assign a unique name to the schedule.
      • Schedule Frequency: Define how often the schedule should run (hourly, daily, weekly, or monthly).
      • Export Time Range: Specify the time range of data to include (e.g., last 24 hours, last 7 days, or custom).
      • Report Format: Choose the preferred format for the exported report (PDF, CSV, XLS).
    • Notification
      • Select Template: Pick a predefined report template or customize one.
    • Rule Details
      • Select Rule: Choose the anomaly rule(s) you want to associate with the schedule. Reports and alerts generated will be based on the selected rules.
    Create scheduled reports in the manage rules module
    Image 4: Create scheduled reports in the manage rules module
  3. Click on Save after making all the required configurations. Upon successful completion of action, the below pop-up appears.
    Create scheduled reports in the manage rules module

To enable/disable a schedule for report(s)

Enabling a schedule

  1. Click on the currently disabled icon Disable under the Actions column to enable the schedule.
  2. As soon as you perform this action, the icon indicates that the schedule is now enabled Enable and the below pop-up message appears briefly.
    Create scheduled reports in the manage rules module

Disabling a schedule

  1. Click on the currently enabled icon Enable under the Actions column to disable the schedule.
  2. As soon as you perform this action, the icon indicates that the schedule is now disabled Disable and the below pop-up message appears briefly.
    Create scheduled reports in the manage rules module

To edit a schedule for report(s)

  1. In the Scheduled Reports module, click on the edit Edit icon under the Actions column.
  2. The Edit Scheduled Reports module appears on the screen.
  3. Make the necessary edits and click on the Update button. Upon successful completion of action, the below pop-up appears.
    Create scheduled reports in the manage rules module

To delete a schedule for report(s)

  1. In the Scheduled Reports module, click on the delete Delete icon under the Actions column.
  2. A Delete Schedule pop-up appears to confirm the action. Click on Yes.
    Delete scheduled reports in the manage rules module
  3. Upon successful completion of action, the below pop-up appears.
    Delete scheduled reports in the manage rules module

Read also

This document explained how to schedule detection reports, configure report details and notifications, and manage actions like enabling, disabling, editing, or deleting schedules.