The EDR solution provides comprehensive Reporting, Audit, and Notification Capabilities that enable administrators and security teams to monitor endpoint security, analyze security events, maintain management server activity records, and receive timely notifications for critical incidents.
The reporting framework supports graphical and tabular reports, automated report retention management, host integrity reporting, multiple export formats, and email-based security notifications.
1. Graphical and Tabular Reports
The EDR solution provides both graphical and tabular reporting capabilities to support different monitoring and analysis requirements.
Graphical Reports
Graphical reports provide visual representation of security and endpoint information, making it easier to identify trends, patterns, and changes across the environment.
Reports can include visual representations of:
- Malware detections
- Security alerts
- Endpoint status
- Threat trends
- Policy compliance
- Host integrity
- License status
- Other security and operational metrics
Tabular Reports
The solution also provides detailed tabular reports containing event-level and endpoint-level information.
Tabular reports can be used for detailed investigation, analysis, auditing, and record keeping.
2. Automated Report Retention and Purging
The solution provides an automatic report retention and purge mechanism.
Administrators can configure a retention duration for historical reports. Once the configured retention period is reached, older reports are automatically purged according to the configured settings.
This helps:
- Control storage consumption
- Maintain an organized reporting database
- Remove outdated information automatically
- Simplify report retention management
3. Host Integrity Reporting
The EDR solution provides a dedicated Host Integrity Report to provide visibility into endpoint compliance.
The report identifies endpoints based on their compliance status, including:
- Compliant Endpoints
- Non-Compliant Endpoints
Administrators can use the Host Integrity Report to quickly identify endpoints that do not meet the defined security or configuration requirements and take appropriate corrective action.
4. Management Server Activity Logging
The solution records management server activities to provide an audit trail of administrative and system operations.
Logged activities can include:
- Administrator login/logout activities
- Policy changes
- Configuration changes
- User and role changes
- Endpoint management activities
- Security configuration changes
- Response actions
- Other relevant Management Console activities
This provides administrators with historical visibility into activities performed on the management infrastructure.
5. Multiple Report Export Formats
Reports generated by the EDR solution can be exported in multiple formats for sharing, analysis, and archival purposes.
Supported export formats include:
- CSV
PDF reports are useful for formal reporting and documentation, while CSV reports allow administrators and analysts to perform further data analysis using spreadsheet or other analytical tools.
6. Email Notifications for Critical Events
The EDR solution provides email notification capabilities for critical security and operational events.
Administrators can configure notifications for important events such as:
- Virus outbreaks
- Ransomware incidents
- Critical malware detections
- Significant security alerts
- License expiry or upcoming license expiration
- Other configured critical events
These notifications help administrators respond quickly without continuously monitoring the Management Console.
7. Virus Outbreak Notifications
When the solution detects a significant increase or outbreak of malware activity across endpoints, it can generate an email notification to configured recipients.
The notification helps security teams quickly identify a potential widespread malware incident and initiate investigation and response activities.
8. Ransomware Incident Notifications
The solution can generate email notifications when ransomware-related activity or incidents are detected.
This provides immediate visibility to security administrators and enables them to initiate appropriate containment and remediation actions.
9. License Expiry Notifications
The solution provides email notifications related to license expiration.
Administrators can receive notifications when a license is approaching its expiration date, helping ensure that license renewal activities can be completed before protection or management capabilities are affected.
10. Centralized Reporting and Notification Framework
The EDR reporting and notification framework provides a centralized approach for:
Monitor → Generate Report → Analyze → Export → Retain → Audit → Notify
This enables security and IT teams to maintain visibility into endpoint security posture, compliance, management activities, and critical security incidents while ensuring important events are communicated to responsible administrators in a timely manner.