Print Download PDF Send Feedback

Previous

Next

Views and Reports

In This Section:

Enabling Views and Reports

Catalog of Views and Reports

Views

Reports

Automatic View and Report Updates

Opening a View or Report

Exporting Views and Reports

Scheduling a View or Report

You can create rich and customizable views and reports for log and event monitoring, that inform key stakeholders about security activities.

Use these GUIs:

Enabling Views and Reports

To enable SmartEvent views and reports, you must install and configure a SmartEvent Server.

Catalog of Views and Reports

In the Logs & Monitor view, click the (+) tab to open a catalog of all views and reports, predefined and customized. Click a view or report to open it.

Catalog_R80.10-134990

Item

Description

1

Open Log View - See and search through the logs from all Log Servers. You can also search the logs from a Log Server that you choose.

Open Audit Logs View - See and search records of actions done by SmartConsole administrators.

These views come from the Log Servers. Other views come from the SmartEvent Server.

2

Compliance View - Optimize your security settings and ensure compliance with regulatory requirements.

3

Views - The list of predefined and customized views. A view is an interactive dashboard made up of widgets. The view tells administrators and other stakeholders about security and network events. Each widget is the output of a query. Widgets can show the information as a chart, table, or some other format. To find out more about the events, double-click a widget to drill down to a more specific view or raw log files.

4

Reports - The list of predefined and customized reports. A report has multiple pages, and applies to the time that the report is generated. There are several predefined reports, and you can create new reports. A reports gives more details than a view. Reports can be customized, filtered, generated and scheduled. You cannot drill down into a report.

5

Favorites - Use this view to collect the views and reports you use the most.

6

Switch to Table View or Thumbnails View - The Table view is the default for views and reports. The Thumbnails view is the default for the Favorites and Recent views and reports

7

Scheduled Tasks - See and edit scheduled tasks.

Archive - Completed and in-progress tasks for generating and exporting reports.

8

External Apps

  • SmartEvent Settings & Policy - The SmartEvent GUI client. Use it for initial setup and to define the SmartEvent Correlation Unit policy. The views in SmartConsole are a replacement for those in the R77.x SmartEvent GUI client.
  • Open Tunnel and User Monitoring - The SmartView Monitor GUI Client. The monitoring views in SmartConsole are a replacement for those in the R77.x SmartView Monitor GUI client, except for Tunnel and User Monitoring.
  • SmartView Web Application - A SmartEvent Web application that you can use to analyze events that occur in your environment. Use it to see an overview of the security information for your environment. It has the same real-time event monitoring and analysis views as SmartConsole, with the convenience of not having to install a client.

 

Views

Views tells administrators and other stakeholders about security and network events. A view is an interactive dashboard made up of widgets. Each widget is the output of a query. A Widget can show information in different formats, for example, a chart or a table.

SmartConsole comes with several predefined views. You can create new views that match your needs, or you can customize an existing view.

In the Logs & Monitor view, clicking the (+) tab opens a catalog of all views and reports, predefined and customized. Double-click a view to open it.

Item

Description

1

Widget- The output of a query. A Widget can show information in different formats, for example, a chart or a table.

2

Drill Down - To find out more about the events, double-click a widget to drill down to a more specific view or raw log files.

3

Options - Customize the view, restore defaults, Hide Identities, export.

4

Queries - Predefined and favorite search queries

5

Time Period - Specify the time periods for the view.

6

Query search bar - Define custom queries using the GUI tools, or manually entering query criteria. Shows the query definition for the most recent query.

Reports

A report has multiple pages, and applies to the time that the report is generated. There are several predefined reports, and you can create new reports. A report gives more details than a view. Reports can be customized, filtered, generated and scheduled. You cannot drill down into a report.

In the Logs & Monitor view, clicking the (+) tab opens a catalog of all views and reports, predefined and customized. Double-click a report to open it.

Item

Description

1

Preview bar - A report is divided onto pages, usually, one view on one page. Editing a report is done per page, in the same way as you edit a view.

2

Options - Customize, and generate a report.

3

Time Period - Specify the time periods for the report.

4

Query Search bar - Define custom queries using the GUI tools, or manually entering query criteria. Shows the query definition for the most recent query.

Automatic View and Report Updates

SmartEvent automatically downloads new predefined views and reports, and downloads updates to existing predefined ones. To allow this, make sure the management server has Internet connectivity to the Check Point Support Center.

Opening a View or Report

Use the predefined graphical views and reports for the most frequently seen security issues. You can also customize the views and reports.

To open a view or report

  1. In SmartConsole, open the Logs & Monitor view.
  2. Click the + tab to open a new tab.
  3. Click Views or Reports.
  4. Select a view or a report, and click Open.
  5. Define the required timeframe, and filter in the search bar.
  6. Click Enter.

Exporting Views and Reports

The Export to PDF and Export to Excel options save the current view or report as a PDF or Excel file, based on the defined filters and time frame.

To export a view or report to PDF or Excel:

  1. In SmartConsole, open the Logs & Monitor view.
  2. Click the + tab to open a new tab.
  3. Click Views or Reports.
  4. Select a view or report.
  5. Click Export to PDF. Optionally:
    • Configure the Period and filter.
    • To automatically send by email to specified recipients each time the view or report runs, configure the Send by email settings

    Alternatively, click Open and from inside the view or report click Options > Export to PDF or Export to Excel.

To see your exported views and reports:

  1. Add a new tab. Click +.
  2. Go to Tasks > Archive.

Generating a Network Activity Report

The Network Activity report shows important firewall connections. For example, top sources, destinations, and services. To create this report, SmartEvent must first index the firewall logs.

To enable the Network Activity Report for R80.10 and higher Gateways:

In SmartConsole, in the Access Control Policy rule, add per Session to the Track settings.

To enable the Network Activity Report for Pre-R80.10 Gateways:

  1. In SmartConsole, open the Logs & Monitor view.
  2. Click the (+) to open a Catalog (new tab).
  3. Click the SmartEvent Settings & Policy link.
  4. In the SmartEvent GUI client > Policy tab, select and expand Consolidated Sessions.
  5. Select Firewall Session.

    Note - this configuration increases the number of events per day by about five times. To avoid a performance impact, make sure the hardware can handle the load.

To run the Network Activity Report:

  1. Open the Logs & Monitor view.
  2. Click the (+) to open a Catalog (new tab).
  3. Click Reports.
  4. Export the Network Activity report.

Scheduling a View or Report

To schedule a view or report you need to define and edit it in SmartConsole.

To schedule a report:

  1. In SmartConsole, open the Logs & Monitor view.
  2. Click the + tab to open a new tab.
  3. Click Views or Reports.
  4. Select a view or a report.
  5. Select Actions > Schedule PDF or Schedule Excel.

    The Schedule page of the Export settings window opens.

  6. Define the recurrence pattern.
  7. Define the Period and Filter.
  8. Optional: Configure email settings to get the scheduled view or report automatically. Click Send by Email.

To see your scheduled views and reports:

  1. In SmartConsole, open the Logs & Monitor view.
  2. Click the + tab to open a new tab.
  3. Select Tasks > Scheduled.

To Learn More About Logging and Monitoring

To learn more about logging and monitoring, see the R80.10 Logging and Monitoring Guide.