LogRhythm Reporting (Beta) provides users with the ability to create their own charts and dashboards using Alarm-related datasets, establishing the foundation for expanded reporting capabilities.
The Beta Reporting Engine is only available for Web Console users on LogRhythm SIEM versions 7.26.0 and above.
The original Reporting Experience remains the main reporting engine. Existing reports have not been affected by the addition of the Beta Reporting Engine, and users can continue to rely on their previously created reports as usual.
Access Reporting Beta
By default, the Reporting (Beta) is only available for the LogRhythm Admin profile. This option can be enabled for other users, granting them access to the new engine.
Assign Permissions for Reporting Beta
To enable the Beta Reporting for a user, in the Client Console:
-
On the main toolbar, click Deployment Manager.
-
On the Tools menu, click Administration, and then click User Profile Manager.
The User Profile Manager window appears and lists the existing User Profiles. -
Click an existing user profile to select it, and then click Properties.
-
On the General tab, under the Allow heading, check Reporting (Beta).
-
Click OK to save the profile and close the User Profile window.
Open Reporting Beta
To access Reporting (Beta), from the Web Console:
-
Click Reports.
The Report window opens. -
Click Reporting Beta in the top-right corner.
The Beta Reporting Engine experience opens.
Create or Edit a Report
To create a new report using the Reporting (Beta) experience, click + Report at the top-left corner of the window to open the Beta Report Editor.
To edit an existing report, click the edit icon in the Actions column (list view), or click the three-dot menu and click Edit (grid view).
Report Components
You can create reports using various components within the Beta Report Editor.
The following components are present in the Beta Report Editor, and understanding them can help you build a better report:
Datasets
Datasets are the groups of information that can be pulled from when creating reports. These datasets contain information that is relevant to analysts, and help analysts make informed decisions once the data is presented through charts in a report. Each dataset supports different out-of-the-box reports.
|
Dataset |
Description |
|---|---|
|
alarms_with_events |
Alarms joined to raw events with source/dest host and IP. Supports: Alarms with Aggregate Events, Alarms with Event Details. |
|
alarms_summary |
Alarm list with entity, rule, status and assigned person. Supports: Alarm List by Entity. |
|
alarms_notification |
Alarm notification delivery records with contact method detail. Supports: Alarm Notification List. |
|
alarms_activity |
Full alarm activity including events, notification summary and history comments. Supports: Alarms with Event and Activity Detail. |
Charts
Charts take the information in a dataset and display it in a visual, dashboard-style arrangement.
Charts can be dragged or dropped into the report editor “canvas” to display the information relevant to you. You can filter and sort charts by using the options at the top of the list. You can also check Show only my charts to only display charts the active user account has created.
Additional options can be created at any time by clicking the +Create new chart or Add Chart buttons, depending on where you are in the editor.
The following options are available by default:
|
Chart |
Description |
|---|---|
|
Top Alarms - Last 7 Days |
Displays a list of the top triggered alarms in the span of the last seven days, with the number of times they’ve been triggered and the % of all alarms triggered accounted for by each alarm. |
|
Open Alarms by Owner |
Displays a bar chart displaying the number of open alarms by their owner. |
|
Open Alarms by Status |
Displays a pie chart of all open alarms based on their current status. |
|
Oldest Open Alarms |
Displays a list of open alarms, with the oldest alarms at the top. |
|
Open Alarms by Risk |
Displays a bar chart of the number of alarms assigned to each risk score. |
|
Alarm Volume Trend |
Displays a trendline displaying the number of alarms created over the last 30 days, compared to the 30 days before that. |
|
Alarm Closure Trend |
Displays a trendline displaying the number of alarms closed over the last 30 days, compared to the 30 days before that. |
Layout Elements
Layout elements allow you to visually configure reports the way you want, putting different information in different places, or dividing information in a way that is suitable to your needs.
|
Element |
Description |
|---|---|
|
Tabs |
Allows you to organize report content into multiple tabbed views, enabling you to group related information into separate sections that users can navigate between by clicking tab headers. |
|
Row |
Allows you to create a separate row within a report, containing charts that have relevant or similar data. |
|
Column |
Allows you to create a separate column within a report, containing charts that have relevant or similar data. |
|
Header |
Allows you to add a header, defining the information below or providing tips for users of the report. |
|
Text/Markdown |
Allows you to create a box with custom text or markdown code, displaying the information you want. |
|
Divider |
Adds a dividing line, keeping different parts of your report separate. |
Report Editor Actions
While creating or editing a report in the report editor, there are multiple actions you can take. These actions are defined below.
|
Action |
Description |
|---|---|
|
Save report |
You can save your report at any time by clicking the Save button at the top-right of the editor. Alternatively, you can click the three-dot menu next to the Save button and then click Save as to name your report, with the option to overwrite the previously saved version of the report if desired. |
|
Undo/Redo |
You can undo or redo an action by clicking the Undo or Redo buttons at the top-right of the editor. |
|
Edit properties |
You can edit various properties of a report by clicking the three-dot menu at the top-right of the editor and then clicking Edit properties. The available properties are described in the section below. |
|
Download |
You can download a report by clicking the three-dot menu at the top-right of the editor and then hovering over Download. You can then choose the format to which you would like to download the report (PDF, Image, YAML, etc). |
|
Favorite |
You can favorite a report at any time by clicking the star icon at the top-left of the report editor. You can unfavorite the report by clicking the star again. |
|
Discard |
You can delete a report’s progress by clicking the Discard button at the top-right of the editor. You will need to verify the action. All charts and layout elements will be removed from the editor, allowing you to start the report over form the beginning. |
Manage the Reporting Beta Window
The Reporting (Beta) experience allows you to change the view, sort, and filter reports to meet your needs.
Change the Report View
You can change the way reports in the Beta experience are displayed by selecting one of the following options in the top-left corner:
|
Option |
Description |
|---|---|
|
Grid View |
Show all created reports as cards in a grid. |
|
List View |
Show all created reports in a columned list that can be sorted. |
Report Actions
You can perform various actions from the main page of the Reporting (Beta) window.
|
Action |
Description |
|---|---|
|
Favorite |
To favorite a report, click the star icon to the left of the report name (list view), or on the report’s card (grid view). |
|
Edit |
To edit an existing report, click the edit icon in the Actions column (list view), or click the three-dot menu and click Edit (grid view). |
|
Delete |
To delete an existing report, click the delete icon in the Actions column (list view), or click the three-dot menu and click Delete (grid view). You will need to type DELETE to confirm the action. |
|
Export |
To export a report, click the export icon in the Actions column (list view), or click the three-dot menu and click Export (grid view). |
|
Bulk select |
Click Bulk select in the top-right corner of the window to enable selection of multiple reports at once. Either check each desired report in the far-left column (list view), or click on each desired report’s card (grid view). You can then click Delete to delete multiple reports at once time, or Deselect all to undo your selections. |
Search and Filter Reports
To search for a report and/or filter report results:
-
In the Name box, enter a search term and press Enter to only display reports that include the term in their name.
-
Optionally, open the drop-list for any of the following options and select criteria by which to filter:
|
Option |
Description |
|---|---|
|
Status |
Select a report status (for example, Draft or Published) to only display reports with the selected status in the list. |
|
Owner |
Select a LogRhythm Web Console user to only show reports owned by the selected user. |
|
Favorite |
Select Yes to only display reports in the list that have been favorited. Select No to display non-favored reports. |
|
Certified |
Select Yes to only display reports that have been certified in the list. Select No to display non-certified reports. |
|
Modified by |
Select a LogRhythm Web Console user to only show reports that have been modified by the selected user. |