Skip to main content

Get Reports from the Cyber Shield Top 10 Dashboard

Abstract

Export Cyber Shield event data from the Top 10 Dashboard — download an immediate CSV filtered by active period and drill level, or request a detailed domain or traffic report by email (three-day link, .zip). Expired links show an error with instructions to request again.

Overview

Export Cyber Shield event data from the Top 10 Dashboard to investigate Domain Filtering and Traffic Filtering activity.

The report reflects the active filters, selected period, and current drill-down level when you request it. For example, if you drill down from a category to a User or Device before requesting the report, the report is scoped to that selection.

Report

What it provides

Delivery

Domain Filtering report

Detailed domain events for the selected period, active filters, and drill level.

Sent by email with a Download Report link.

Traffic Filtering report

Detailed traffic events for the selected period, active filters, and drill level.

Sent by email with a Download Report link.

The email provides a three-day download link. Selecting Download Report downloads a .csv.zip file that can contain one or more CSV files.

Note

If the download link is expired or invalid, CloudConnexa displays an error and guidance on requesting the report again.

Get a Domain Filtering report

Use the Top 10 Dashboard to export detailed Domain Filtering events for the current view.

  1. Navigate to Shield → Overview.

  2. Scroll to the Top 10 Dashboard.

  3. Display the Domain Filtering data you want to investigate.

  4. Set the desired period and other filters.

  5. Drill down to the desired category, User, or Device, if needed.

  6. Select Export All Events to CSV.

    • A message confirms that the report will be sent to the Owner's email address shortly.

    Tip

    The requested report reflects the active filters, period, and drill level displayed when you selected Export All Events to CSV.

Download the Domain Filtering report

  1. Open the report email sent by CloudConnexa.

  2. Select Download Report.

  3. If prompted, sign in to your CloudConnexa Administration portal.

    • CloudConnexa opens the Administration portal and starts the report download. A confirmation displays when the download starts. The report downloads as a .csv.zip file and can contain one or more CSV files.

    Note

    The email provides a three-day download link. If you use an expired link or invalid link, CloudConnexa displays an error with guidance to request the report again.

Domain Filtering report fields

The Domain Filtering report contains the following fields for observed or blocked domain events:

Field

Description

Day

Date of the events.

Domain

Domain name queried.

Hit count

Number of domain resolutions for the domain during the interval.

First resolve time

Time the domain was first resolved during the day.

Last resolve time

Time the domain was last resolved during the day.

Category

Content category assigned to the domain.

User

User associated with the DNS query, when applicable.

Host

Host associated with the DNS query, when applicable.

Network

Network associated with the DNS query, when applicable.

Device

Device associated with the DNS query, when applicable.

Connector

Connector associated with the DNS query, when applicable.

Get a Traffic Filtering report

Use the Top 10 Dashboard to export detailed Traffic Filtering events for the current view.

  1. Navigate to Shield → Overview.

  2. Scroll to the Top 10 Dashboard.

  3. Display the Traffic Filtering data you want to investigate.

  4. Set the desired period and other filters.

  5. Drill down to the desired category, User, or Device, if needed.

  6. Select Export All Events to CSV.

    • A message confirms that the report will be sent to the Owner's email address shortly.

    Tip

    The requested report reflects the active filters, period, and drill level displayed when you selected Export All Events to CSV.

Download the Traffic Filtering report

  1. Open the report email sent by CloudConnexa.

  2. Select Download Report.

  3. If prompted, sign in to your CloudConnexa Administration portal.

    • CloudConnexa opens the Administration portal and starts the report download. A confirmation displays when the download starts. The report downloads as a .csv.zip file and can contain one or more CSV files.

    Note

    The email provides a three-day download link. If you use an expired link or invalid link, CloudConnexa displays an error with guidance to request the report again.

Traffic Filtering report fields

The Traffic Filtering report contains the following fields for observed or blocked domain events:

Field

Description

Day

Date of the events.

Hit count

Number of domain resolutions for the domain during the interval.

First occurrence

Time the first event occurred.

Last occurrence

Time the last event occurred.

Threat signature

Unique ID of the matched traffic signature.

Event

Name of the detected event.

Category

Threat category assigned to the event.

Classification

Classification assigned to the event.

Priority

Threat priority assigned to the event.

Protocol

Network protocol associated with the traffic.

Source IP

Source IP address of the traffic.

Source Ports

Source ports associated with the traffic.

Destination Ports

Destination ports associated with the traffic.

Source User

User associated with the traffic, when applicable.

Source Device

Device associated with the traffic, when applicable.

Source Host

Host associated with the traffic, when applicable.

Source Network

Network associated with the traffic, when applicable.

Source Connector

Connector associated with the traffic, when applicable.

isBlocked

Indicates whether the traffic was blocked.

How the report scope is determined

Export All Events to CSV uses the current state of the Top 10 Dashboard to determine which events are included in the report.

Dashboard selection

Effect on the report

Period

Includes events from the selected period.

Active filters

Includes events that match the filters currently applied.

Filtering type

Includes events for the Domain Filtering or Traffic Filtering view you're using.

Drill level

Limits the report to the current category, User, or Device when you've drilled down.