Reporting, Audit and Notification Capabilities

The EDR solution provides comprehensive Reporting, Audit, and Notification Capabilities that enable administrators and security teams to monitor endpoint security, analyze security events, maintain management server activity records, and receive timely notifications for critical incidents.

The reporting framework supports graphical and tabular reports, automated report retention management, host integrity reporting, multiple export formats, and email-based security notifications.

1. Graphical and Tabular Reports

The EDR solution provides both graphical and tabular reporting capabilities to support different monitoring and analysis requirements.

Graphical Reports

Graphical reports provide visual representation of security and endpoint information, making it easier to identify trends, patterns, and changes across the environment.

Reports can include visual representations of:

  • Malware detections
  • Security alerts
  • Endpoint status
  • Threat trends
  • Policy compliance
  • Host integrity
  • License status
  • Other security and operational metrics

Tabular Reports

The solution also provides detailed tabular reports containing event-level and endpoint-level information.

Tabular reports can be used for detailed investigation, analysis, auditing, and record keeping.

2. Automated Report Retention and Purging

The solution provides an automatic report retention and purge mechanism.

Administrators can configure a retention duration for historical reports. Once the configured retention period is reached, older reports are automatically purged according to the configured settings.

This helps:

  • Control storage consumption
  • Maintain an organized reporting database
  • Remove outdated information automatically
  • Simplify report retention management

3. Host Integrity Reporting

The EDR solution provides a dedicated Host Integrity Report to provide visibility into endpoint compliance.

The report identifies endpoints based on their compliance status, including:

  • Compliant Endpoints
  • Non-Compliant Endpoints

Administrators can use the Host Integrity Report to quickly identify endpoints that do not meet the defined security or configuration requirements and take appropriate corrective action.

4. Management Server Activity Logging

The solution records management server activities to provide an audit trail of administrative and system operations.

Logged activities can include:

  • Administrator login/logout activities
  • Policy changes
  • Configuration changes
  • User and role changes
  • Endpoint management activities
  • Security configuration changes
  • Response actions
  • Other relevant Management Console activities

This provides administrators with historical visibility into activities performed on the management infrastructure.

5. Multiple Report Export Formats

Reports generated by the EDR solution can be exported in multiple formats for sharing, analysis, and archival purposes.

Supported export formats include:

  • PDF
  • CSV

PDF reports are useful for formal reporting and documentation, while CSV reports allow administrators and analysts to perform further data analysis using spreadsheet or other analytical tools.

6. Email Notifications for Critical Events

The EDR solution provides email notification capabilities for critical security and operational events.

Administrators can configure notifications for important events such as:

  • Virus outbreaks
  • Ransomware incidents
  • Critical malware detections
  • Significant security alerts
  • License expiry or upcoming license expiration
  • Other configured critical events

These notifications help administrators respond quickly without continuously monitoring the Management Console.

7. Virus Outbreak Notifications

When the solution detects a significant increase or outbreak of malware activity across endpoints, it can generate an email notification to configured recipients.

The notification helps security teams quickly identify a potential widespread malware incident and initiate investigation and response activities.

8. Ransomware Incident Notifications

The solution can generate email notifications when ransomware-related activity or incidents are detected.

This provides immediate visibility to security administrators and enables them to initiate appropriate containment and remediation actions.

9. License Expiry Notifications

The solution provides email notifications related to license expiration.

Administrators can receive notifications when a license is approaching its expiration date, helping ensure that license renewal activities can be completed before protection or management capabilities are affected.

10. Centralized Reporting and Notification Framework

The EDR reporting and notification framework provides a centralized approach for:

Monitor → Generate Report → Analyze → Export → Retain → Audit → Notify

This enables security and IT teams to maintain visibility into endpoint security posture, compliance, management activities, and critical security incidents while ensuring important events are communicated to responsible administrators in a timely manner.