セキュリティイベントレポートの生成

Prev Next

この記事では、アカウントのために生成するCatoセキュリティイベントレポートの作成方法について説明します。

概要

Catoは、アカウントのセキュリティサービスで生成されたイベントに基づく活動を要約する定義済みレポートテンプレートを提供します。

レポートで含まれるサイトとSDPユーザーを含む、一度限りまたは定期的なレポートのテンプレートを作成します。 デフォルトでは、過去一週間の全てのサイトとSDPユーザーのトラフィックとデータを表示するセキュリティイベントレポートのテンプレートを使用します。

レポートに関する詳細情報については、Cato Reportsを参照してください。

定期的なセキュリティイベントレポートの作成

Create a new recurring report by defining the Filters for the items included in the report, as well as the Schedule which defines how often the report is generated - every two minutes, daily, weekly, or monthly. Generated reports are stored in the Cato Cloud, and they can be automatically emailed or downloaded. The Schedule also defines the time range that is covered by each report.

You can select a mailing list of email addresses for the recipients, which can include Cato Management Application admins, and external users.

For more information about Mailing Lists, see Working with Mailing Lists.

To create a recurring report:

  1. From the navigation pane, select Home > Reports.

  2. From the Catalog tab, find and select the template you want to use to generate the report.

  3. Click Generate > Create Schedule.

  4. Enter a Report Name.

  5. (Optional) In Filters, select specific sites or users for the predefined report.

    By default, the predefined report includes all sites and users.

  6. Define when the report will be generated and sent:

    1. Select the Frequency.

    2. For Weekly and Monthly scheduled reports, in Every select the day that the report is sent.

    3. Select the timezone.

  7. Select the export format: PDF or CSV.

  8. In Subscriptions, select the Mailing List that receives the report.

    You can click New to create a new mailing list.

  9. Click Save Schedule. The report is added to the Saved Reports tab.

Generating a Recurring Report On Demand

Recurring reports are automatically generated based on their schedule settings. For example, a weekly report configured for Monday, is generated every Monday. You can also choose to manually generate a recurring report on demand, in which case the generated report uses the defined time range based on the current day. If an admin manually generates a weekly report on a Tuesday, the time range for the report is the previous 7 days starting from that Tuesday, regardless of the starting day of the recurring report. For more information about the time range of recurring reports, see Cato Reports.

To generate a recurring report on demand:

  1. From the navigation pane, select Home > Reports.

  2. From the Saved Reports tab, find the recurring report and click Generate Now.

  3. From the Generated PDFs tab, find the report and click Download.

一度限りのセキュリティイベントレポートの作成

セキュリティイベントテンプレートに基づいた一度限りのレポートを作成できます。 レポートに含まれるアイテムに関するフィルターを定義します。

To create a one-time report:

  1. From the navigation pane, select Home > Reports.

  2. From the Catalog tab, select the template you want to use to generate the report.

  3. Select Generate > Generate Now.

  4. Enter a Report Name.

  5. Define the relevant Filters for your report.
    These are specific to the report type.

  6. Define the Timeframe and Timezone of the report.

  7. Select the Format: PDF or CSV.

  8. Click Generate.
    The report is generated, and you can download it from the Generated tab.

セキュリティレポートの理解

レポートにはセキュリティサービスのトップイベントを表示するセクションがあり、そのセクションでは最大12のアイテムが表示されます。

セキュリティレポートのセクションは以下の通りです:

  • セキュリティイベントの概要

    • ブロックされたセキュリティイベント: アカウントに対して有効化されているセキュリティエンジンの全てのブロックイベントを示すグラフ

    • 最も多くブロックされたイベント: ブロックイベントに基づくトップセキュリティエンジン、および各エンジンのイベント数

    • トップサイト - セキュリティイベント(ブロック済み): ブロックイベントを生成するトラフィックのあるトップサイト

    • トップユーザー - セキュリティイベント(ブロック済み): ブロックイベントを生成したトップユーザー

  • インターネットファイアウォール

    • ブロックとプロンプトイベント: インターネットファイアウォールのプロンプト、ブロック、またはRBIルールアクションに基づくイベントを示すグラフ

    • 許可イベント: インターネットファイアウォールルールが一致した際にイベントを生成するモニタアクションを持つルールのイベントを示すグラフ

    • トップブロックアプリ: ヒット数があるインターネットファイアウォールでブロックされたトップアプリ

    • トップブロックカテゴリ: ヒット数があるインターネットファイアウォールでブロックされたトップカテゴリ

    • トップブロックドメイン: ヒット数があるインターネットファイアウォールでブロックされたトップドメイン

  • WANファイアウォール

    • ブロックおよびプロンプトイベント: WANファイアウォールのプロンプトまたはブロックルールアクションによるブロックイベントを示すグラフ

    • 許可イベント: ルールが一致した際にイベントを生成するモニタアクションを持つWANファイアウォールルールのイベントを示すグラフ

    • トップブロックアプリ: ブロック回数のあるWANファイアウォールでブロックされたトップアプリ

    • トップブロックカテゴリ: ブロック回数のあるWANファイアウォールでブロックされたトップカテゴリ

    • トップブロックドメイン: ブロック回数のあるWANファイアウォールでブロックされたトップドメイン

  • IPSイベント

    • トップの脅威: 各脅威のイベント数とともに、IPSサービスによりブロックされたトップの脅威名

    • ブロックイベント: レポートの期間内でIPSサービスの全てのブロックイベントを示すグラフ

    • 脅威タイプ: ブロックされたIPS脅威タイプの割合を示すチャート

    • リスクレベル: IPSブロックイベントのリスクレベルの割合を示すチャート

    • トラフィック方向: IPSブロックイベントのトラフィック方向の割合を示すチャート

  • マルウェアイベント

    • トップ検出: マルウェア対策サービスでブロックされた脅威名の上位と、それぞれの脅威のイベント数

    • ブロックイベント: レポートの期間内でマルウェア対策サービスでの全てのブロックイベントを示すグラフ

    • 脅威タイプ: マルウェア対策サービスによって特定された脅威タイプの割合を示すチャート

    • マルウェア対策アクション: マルウェア対策サービスによるアクションの割合を示すチャート

    • 陽性検出があったソース: マルウェア対策サービスが脅威を検出したソース(サイトまたはSDPユーザー)のリスト

  • 疑わしい活動イベント

    • トップ脅威: 各脅威のイベント数と共に、IPSサービスのSAMエンジンによって特定された上位脅威名

    • 監視イベント: レポートの期間におけるSAMエンジンのモニタイベントを示すグラフ

    • 脅威タイプ: SAMエンジンによって特定された脅威タイプの割合を示すチャート

    • リスクレベル: SAMイベントのリスクレベルの割合を示すチャート

    • トラフィック方向: SAMイベントのトラフィック方向の割合を示すチャート

  • DNS保護イベント

    • 脅威タイプ: DNS保護エンジンによってブロックされた脅威タイプの割合を示すチャート

    • トップドメイン: DNS保護エンジンによってブロックされたトップドメインとヒット数

    • DNS保護のトップホスト: ブロックイベントがあったDNS保護のトップホストとヒット数