Generate Forescout eyeSight reports and logs

Your Forescout Console is equipped with powerful report generation tools.

On-Screen Threat Protection Reports

These reports provide you with important system information about policies and detections; the services most frequently targeted by malicious endpoints; the origin of a worm outbreak or the infected endpoints in each network segment. You can also generate detailed reports on events, such as the number of probe and infection attempts per host or service, or the number and types of marks distributed over a time period. See On-Screen Threat Protection Reporting for details.

Real-time reports

You can generate comprehensive real-time reports regarding policy detections and endpoint discovery information. See Reports Portal for details.

Automated updates to these reports are available via the Modules pane.

Audit trails reports

You can view user audit trail reports that contain information about user activities during a specified time period. These reports can be exported. See Monitoring User Activity for details.

Forescout eyeSight On-Screen Threat Protection Reporting

 

This section details the Console reports.

Report results display activity that occurred within a specified time range for the Appliances that you select. For example, you can generate a report that covers a two-day, two-week, or two-month period, for one, several, or all the Appliances in your enterprise. By default, all Appliances are selected.

Note: Reports may include information about both bites and infection attempt events. The bite event is the event in which the endpoint used a mark to try and gain access to your network. An infection attempt event is an event followed by a bite event that is detected at an open, real port on the service where the bite event was detected.

Executive reports

The Executive Report provides a concise overview of important Forescout platform and endpoint activities.

Report Details

Executive Summary

A detailed briefing of malicious endpoints activity and policy detections in your network during a specified time period.

The report provides:

  • Information about endpoints detected via the policy.
  • Top 10 infected endpoints. The report shows the IP address of the endpoints that have carried out the most infection attempts, and the number of infection attempts carried out
  • Infected/Targeted Hosts per Service: Shows the number of infected endpoints that attempted to infect a service, and the number of endpoints in the network at which an infection attempt was carried out for that service
  • Event summary showing important Forescout platform and endpoint events..

Report customization options let you adjust the following for the top 10 reports:

  • Display only results greater than a set value.
  • Update, for example, the top 10 value to top five or top 15.

Operational reports

 

Operational reports provide extensive information about probe, scan, bite, and infection attempt events that occur at targets, endpoints and services in your network. These reports allow in-depth drill-down of security information gathered by Forescout products.

Report Details

External Blocking

Provides information about external blocking activity, including:

  • Domains targeted outside your network and blocked
  • Endpoints that attempted to infect domains outside your network..
  • Infection attempts targeted at domains outside your network.

By default, the top 10 infected endpoints are displayed. This value can be changed from the Report Options dialog box.

The following reports show information about infected endpoints in your network.

Report Details

Worm Originator

Displays the origin of a worm outbreak, tracking down the worm host to where it was originally detected in your network.

Infected Hosts by Segment

Displays the infected endpoints in your network, sorted by segment.

Report options let you generate a table that lists the details of all the events shown in the report.

Infected hosts by Service

Displays the infected endpoints in your network, sorted by service.

Report options let you generate a table that lists the details of all the events shown in the report.

Top Worm-Infected Hosts

Displays the IP addresses of infected endpoints that carried out the most infection attempts.

By default, the top 10 infected endpoints are displayed. This value can be changed from the Report Options dialog box.

Report customization options also allow you to:

  • Display only results greater than a set value. For example, show results only if infected endpoints initiated more than 10 infection attempts.
  • Generate a table detailing report events.

The following reports give results of endpoint probing.

Report Details

Probing Hosts by Segment

Displays the probing endpoints in your network, sorted by segment.

Probing Host by Service

Displays the probing endpoints in your network, sorted by service.

The following reports give details of email worm infection attempts.

Report Details

Top email Infected Hosts

Displays the endpoints in your network that generated the most email worm infection attempts. By default, results are limited to the 10 most active endpoints. You can change the default setting. Additional report customization options let you display only results greater than a set value. For example, show the results only if the endpoints generated more than five email events.

Email Infected Hosts per Segment

Lists endpoints in your network that generated email worm infection attempts, sorted by segment. Important information about each endpoint is presented, including the email address from which the attempt was made, the number of senders, and the number of mails sent.

Related Worm Names for Hosts

Displays endpoints, and names of high-profile worms that performed activities similar to that of the endpoint.

You can load the most current related attack name file by selecting Load Related Attack Names from the Tools menu. This option installs new related worm names and the associated services that they attacked. Updated files can be found on the support page of the Forescout website.

The following reports display information about infection attempts that occurred at the endpoints in your network.

Report Details

Top Infection Attempts per Host

Displays the most frequently targeted real endpoints in your network. The report lists the endpoint IP addresses and the number of infection attempts at each real endpoint.

By default, the 10 most frequently targeted, real endpoints are displayed. This value can be changed from the Report Options dialog box.

Additional report customization options let you display only results greater than a set value. For example, show the results only if the real endpoint was targeted more than 10 times.

Infection Attempt Summary for a Selected Host

Displays all infection attempts that targeted a specific endpoint.

Report options let you generate a table that lists the details of all the events shown in the report. For example, the date and time the event occurred and the endpoint IP address that initiated the event.

The following reports display information about services targeted in your network.

Report Details

Infected Hosts / Targeted Hosts per Service

Shows the number of infected endpoints that attempted to infect a service, and the number of endpoints in the network at which an infection attempt was carried out for that service.

Report customization options let you adjust the following for the top 10 reports:

  • Results greater than a set value (calculated according to infected endpoints).
  • Update, for example, the top 10 value to top five or top 15 (calculated according to infected endpoints).

Top Infection Attempts per Service

Displays the top infection attempts per service.

The report displays the service and the number of infection attempts at each service.

This lets you evaluate which services in your network are more attractive to worms and can help in analyzing the security mechanism protecting these services.

By default, the 10 most frequently targeted services are displayed. This value can be changed from the Report Options dialog box.

Additional options let you display only results greater than a set value, for example, display a service only if it was attacked more than 10 times.

The following report display information about Scan policy results.

Report Details

Scan Results

Displays information regarding vulnerable machines detected in your network. The report lists the name of the vulnerability, the number of machines at which it was detected, as well as the number of services closed.

By default, the 10 most common vulnerabilities detected in your network are displayed. This value can be changed from the Report Options dialog box.

Report customization options allow you to:

Display only results greater than a set value.

Generate a table detailing report events.

The following reports show activity statistics.

Report Details

Infection Attempts Over Time

Displays the number of infection attempt events that occurred during a specified time period.

Report customization options allow you to:

Define the intervals at which results are displayed, i.e., hourly, daily, or weekly.

Generate a table detailing report events.

Scan Detections Over Time

Displays the numbers of scan events that occurred during a specified time period. Report customization options allow you to:

  • Define the intervals at which results are displayed, i.e., hourly, daily, or weekly.
  • Generate a table detailing report events.

Top Bite Methods

Displays the most common bite methods used over a specified time period, as well as the number of times each method was used.

By default, the top 10 bite methods are displayed. You can update this value from the Report Options dialog box. Report customization options also allow you to:

  • Display only results greater than a set value. For example, display results for a method only if the method was used more than 10 times.
  • Generate a table detailing report events.

Top Scan Methods

Displays the most common scan methods used over a specified time period as well as the number of times each method was used.

By default, the top 10 scan methods are displayed. You can update this value from the Report Options dialog box. Report customization options also allow you to:

  • Display only results greater than a set value. For example, display results for a method only if the method was used more than 10 times.
  • Generate a table detailing report events.

Top Mark Types

Displays the top mark types distributed during a specified time period, as well as the number of times each mark type was distributed.

By default, the 10 most frequently distributed mark types are displayed. You can update this value from the Report Options dialog box.

Report customization options also allow you to:

  • Display only results greater than a set value. For example, display results for a mark type only if the mark was distributed more than 10 times.
  • Generate a table detailing report events.

Top Always Allowed Services

Shows the always allowed services that were most frequently accessed by blocked endpoints. Always allowed services are defined when creating exception rules from the Virtual Firewall pane.

The results of this report help you evaluate the implications of maintaining always allowed services.

By default, the 10 always allowed services that were most frequently accessed are displayed. This value can be changed from the Report Options dialog box.

Report customization options also let you:

  • Display only results greater than a set value. For example, only show services that were accessed more than 10 times.
  • Generate a table detailing report events.

See Managing Your Virtual Firewall Policy for details.

The following report displays information per Appliance.

Report Details

Hosts Per Appliance

Displays the number of endpoints handled at each Appliance in your enterprise as well as the average for all Appliances. By default, all Appliances are displayed.

Generate on-screen threat protection reports

You can generate reports on-screen and access the on-screen management tools, such as printing and exporting reports.

To generate a report, select Reports > Threat Protection Reports > New.

Reports

To display a list of open report windows, select Window > Reports and then select the report to open.

In a report window, select View > Report Definitions to display the definitions used to generate the report.

Customize reports

Reports are generated with default customization options. These options can be modified so that you can better manage results and view information that is important to you. The following report customization options are available for reports. Not all customization options are applicable to all reports.

If you update a default, it is only applied to the current report; after the report is generated, the default is restored.

In the Reports dialog box, select a report and time period, then select Options.

images/image536.png

Results will be displayed at intervals of
Enter a numerical value and select a time unit.
Limit result number to top
The number of top results to display. For example, enter 5 to report the five endpoints with the most events.
Only show results greater than
Enter a thresholds value. For example, enter 20 to only report endpoints on which 20 events occurred.
Generate event detail table
When this option is enabled more detailed information is available from the report toolbar.

Work with on-screen report management tools

On-screen tools are available to manage and navigate your reports. These tools can be accessed from the menus and the report toolbar.

images/image537.jpg

images/image538.pngimages/image539.png
First/Last Page
Moves to the first or last page of the report. (Only available when the report is displayed in print layout view).
images/image540.pngimages/image541.png
Previous/Next Page
Moves to the previous or next page of report. (Only available when the report is displayed in print layout view).
 images/image542.jpeg
Print Report
Sends the report to the printer.
images/image543.jpeg
Save
Saves the current report to a file. The file is automatically saved to a default location, which you can change if required.
You can open saved reports from the Reports menu on the Console.
images/image544.jpegimages/image542.jpeg
Print/Normal Layout View
Displays the report in print layout view or normal layout view. The cover page and the header and footer are visible in print layout view.
images/image545.jpeg
Displays the report chart or the event detail table, if you generated one.

Save reports

The reports you save are stored by default at the location where you installed the Console.

Select Reports > Threat Protection Reports > Manually Saved Reports to open a saved report.

To change the location for manually saved reports, select Options > Console Preferences > Misc > Reports.

Reports portal

You can access a web-based Reports Portal to generate comprehensive real-time and trend information about policies, vulnerabilities and the network inventory.

The Reports Portal is enabled by the Reports Plugin, a component of the Forescout Core Extensions Module.

Note: Reports may include information about both bites and infection attempt events. The bite event is the event in which the endpoint used a mark to try and gain access to your network. An infection attempt event is an event followed by a bite event that is detected at an open, real port on the service where the bite event was detected.

To access the portal, see Logging In to Forescout Web Portals.

The Reports Plugin lets you generate reports with real-time and trend information about policies, host compliance status, vulnerabilities, device details, assets and network guests.

Use reports to keep network administrators, executives, the Help Desk, IT teams, security teams or other enterprise teams well-informed about network activity. Reports can be used, for example, to help you understand:

  • Long term network compliance progress/trends
  • Immediate security needs
  • Compliance with policies
  • Status of a specific policy
  • Network device statistics

You can create reports and view them immediately, save reports or generate schedules to ensure that network activity and detections are automatically and consistently reported.

In addition, you can use any language supported by your operating system to generate reports. Reports can be viewed and printed as either PDF or CSV files.

To add a report, select Add from the Reports portal home page. Select a report template, then select Next to define parameters and generate the report.

Add Report Template

Work with system event logs

You can view logs about system activity, for example, successful and failed user login operations.

Not all users have access to this feature.

An option is also available to forward various event messages to third-party logging systems via the Syslog Plugin. For details, refer to the Syslog Plugin Configuration Guide..

To view events, select Log > Event Viewer from the Console menu, and define a time period.

images/image548.png

The following information is available:

Severity
The severity level of a system event indicated by a colored icon.
images/image549.png Emergency
images/image550.png Alert
images/image551.png Critical
images/image552.png Error
images/image553.png Warning
images/image554.png Notice
images/image555.png Information
images/image556.png Debug
Date
The date and time when the event occurred.
Status
Whether the operation succeeded or failed.
Element
The resource or component the operation was performed upon (for example, users).
Event
The name of the event that occurred.

Double-click an entry in the log to view more details about the event.

Select File > Clear All to clear all data from the table. This information remains in the system. Select File > Reload to load the latest data from the database.

Select Edit > Find to search for a text string in the event viewer.

Select File > Exports to save the log to a TXT or XLS file.

View block events

A Block Events log provides an at-a-glance display of the block events for the Virtual Firewall (VFW) and threat detections. For example:

  • Host blocks
  • Port blocks
  • External Port blocks
  • External Host blocks
  • Services closed as a result of service attacks
  • Services closed as a result of the blocking rules that you defined via the Virtual Firewall

Use the log to troubleshoot problematic network block events. You can export the information to a CSV file.

Note: These events are sent automatically to the Syslog server. If you do not want to send them, configure the Forescout Syslog Plugin to not transfer this information. Select Tools > Options > Modules > Core Extensions > Syslog > Configure > Events filtering .
Note: Block event logs do not provide Switch or WLAN block events at this time.

To view blocked events, select Blocking Logs from the Log menu, and then define a time period.

The following information is available:

Host
The endpoint that was blocked.
Target
The IP address to which the blocked endpoint attempted to connect.
Time
The time when the endpoint was blocked.
Service
The service at which the endpoint was detected when it was blocked.
images/image558.png
Indicates whether the block event was the result of a Virtual Firewall block rule.
Reason
The reason the source was blocked.

Select View > Find to search for text.

If you selected a relative time when generating the block events list, select File > Refresh to include events blocked from the indicated start time, up to and including the current time while the dialog box is open.

View a history of monitored and blocked services

Your system policy may be defined so that your system monitors or blocks selected services in your network. You can view a history of the services that were monitored or blocked during a specific time period.

For information about how to work with these policy definitions, see Handling Service Attacks

Select Log > Service Attack History and define a time period.

The following information is available:

Service
Displays the port and protocol of service.
State
Displays the state, i.e., if the service was blocked or monitored. Use your cursor to view a tooltip that lists the IP addresses of endpoints that scanned the service, and the endpoint IP addresses that they probed.
Normal indicates that the service state was removed.
Date
Displays the date and time when the monitor or block state was initiated.
Related Worms
Displays the name of a related worm. A related worm is the name of a known worm that performed events similar to the events carried out by sources in your system.
For example, if a source scans port 1434/UDP more than once, the worm name Slammer is displayed as a related worm name because this is the service that the Slammer worm attacked.
Appliance
Displays the dedicated device that monitors traffic going through your corporate network.