Reports
|
Reports |
Applicable Frameworks |
Data Source |
Intelligent Indexing |
Classification |
Log Sources |
|---|---|---|---|---|---|
|
CCF: Access Failure Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Audit |
All Available Log Sources |
|
CCF: Access Success Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Audit |
All Available Log Sources |
|
CCF: Account Deleted Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Audit |
All Available Log Sources |
|
CCF: Account Disabled Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
LogMart |
No |
Audit |
All Available Log Sources |
|
CCF: Account Enabled Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Audit |
All Available Log Sources |
|
CCF: Account Modification Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Audit |
All Available Log Sources |
|
CCF: Applications Accessed By User Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
No |
Operations |
All Available Log Sources |
|
CCF: Audit Log Summary |
UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Audit |
All Available Log Sources |
|
CCF: Auth Failure Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Audit |
All Available Log Sources |
|
CCF: Auth Success Summary |
NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Audit |
All Available Log Sources |
|
CCF: Backup Activity Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
No |
Operations |
All Available Log Sources |
|
CCF: Compromises Detected Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
LogMart |
Yes |
Security |
All Available Log Sources |
|
CCF: Config/Policy Change Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
LogMart |
Yes |
Audit |
All Available Log Sources |
|
CCF: Critical Environment Error Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Operations |
All Available Log Sources |
|
CCF: GeoIP Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Security |
All Available Log Sources |
|
CCF: Host Access Granted And Revoked Detail |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Audit |
All Available Log Sources |
|
CCF: LogRhythm Data Loss Defender Log Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
LogMart |
Yes |
Operations |
All Available Log Sources |
|
CCF: Malware Detected Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Security |
All Available Log Sources |
|
CCF: Object Access Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
No |
Audit |
All Available Log Sources |
|
CCF: Patch Activity Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Operations |
All Available Log Sources |
|
CCF: Physical Access Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Audit |
All Available Log Sources |
|
CCF: Priv Account Management Activity Summary |
UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Audit |
All Available Log Sources |
|
CCF: Priv Authentication Activity Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Audit |
All Available Log Sources |
|
CCF: Rogue Access Point Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Security |
All Available Log Sources |
|
CCF: Signature Activity Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
LogMart |
Yes |
Operations |
All Available Log Sources |
|
CCF: Social Media Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Audit |
All Available Log Sources |
|
CCF: Suspected Wireless Attack Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Security |
All Available Log Sources |
|
CCF: Term Account Activity Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Audit |
All Available Log Sources |
|
CCF: Time Sync Error Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Operations |
All Available Log Sources |
|
CCF: Top Suspicious Users |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Security |
All Available Log Sources |
|
CCF: Unknown User Account Detail |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Security |
All Available Log Sources |
|
CCF: Use Of Non- Encrypted Protocols Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
LogMart |
Yes |
Audit |
All Available Log Sources |
|
CCF: User Misuse Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
No |
Security |
All Available Log Sources |
|
CCF: User Object Access Summary |
GDPR, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Audit |
All Available Log Sources |
|
CCF: User Priv Escalation (SU & SUDO) Summary |
UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS, State DPLs |
Data Processor(s) |
Yes |
Audit |
All Available Log Sources |
|
CCF: User Priv Escalation (Windows) Summary |
UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Audit |
All Available Log Sources |
|
CCF: Vulnerability Detected Summary |
GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs |
Platform Manager |
Yes |
Security |
All Available Log Sources |
Reporting Packages
|
Report Package Name |
Report Package Description |
Report Package ID |
|---|---|---|
|
CCF: Daily IT Operations Reporting Package |
This Reporting Package is a template to deliver pertinent content for IT Operations on a daily basis. |
89 |
|
CCF: Daily IT Security Reporting Package |
This Reporting Package is a template to deliver pertinent content for IT Security on a daily basis. |
90 |
|
CCF: Executive Reporting Package |
This reporting package is a template to deliver pertinent content for Executives on a monthly basis. |
87 |
|
CCF: Weekly Audit Reporting Package |
This Reporting Package is a template to deliver pertinent content for Internal and/or External Audit groups on a weekly basis. |
88 |
Customize a Report Package by Cloning
The CCF Report Packages provide default report selections for their intended audiences. To fully customize a Report Package, clone the package rather than editing the default package directly.
Use the following workflow:
-
Open the Report Center.
-
Select the Report Packages tab.
-
Select the check box for the report package you want to customize and use.
-
Right-click the selected report package, and then select Clone.
-
Customize the package settings and report selections. Select Next to move through each configuration section.
-
When the Save option becomes available, review the configuration and save the cloned Report Package.
-
After the cloned Report Package is saved, configure a schedule if the package should run automatically.
Report results depend on the log sources, scope, lists, entities, and other configuration available in the environment. Review and customize the cloned package for the organization before scheduling it for production use.
Default Reports Included in Each CCF Report Package
The following reports are selected by default in the updated CCF Report Packages.
CCF: Daily IT Operations Report Package (ID 89)
|
Report Name |
Report ID |
|---|---|
|
CCF: Backup Activity Summary |
2062 |
|
CCF: Config/Policy Change Summary |
2049 |
|
CCF: Critical Environment Error Summary |
2050 |
|
CCF: Patch Activity Summary |
2052 |
CCF: Daily IT Security Report Package (ID 90)
|
Report Name |
Report ID |
|---|---|
|
CCF: Auth Failure Summary |
2088 |
|
CCF: Auth Success Summary |
2090 |
|
CCF: Compromises Detected Summary |
2064 |
|
CCF: Malware Detected Summary |
2051 |
CCF: Executive Report Package (ID 87)
|
Report Name |
Report ID |
|---|---|
|
CCF: Top Suspicious Users |
2059 |
|
CCF: User Misuse Summary |
2061 |
|
CCF: Vulnerability Detected Summary |
2058 |
CCF: Weekly Audit Report Package (ID 88)
|
Report Name |
Report ID |
|---|---|
|
CCF: Access Failure Summary |
2089 |
|
CCF: Access Success Summary |
2091 |
|
CCF: Account Deleted Summary |
2086 |
|
CCF: Account Disabled Summary |
2084 |
|
CCF: Account Enabled Summary |
2085 |
|
CCF: Account Modification Summary |
2092 |
|
CCF: Audit Log Summary |
2076 |
|
CCF: Term Account Activity Summary |
2087 |