---
title: "Security Activity Report"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35437599/Security%20Activity%20Report"
format: markdown
---
<span style="color: #000000">The </span><span style="color: #000000">*Security Activity Report *</span><span style="color: #000000">provides comprehensive security and traffic data in your network over a specified time period. The report includes data on redirecting, blocking, allowing, and interacting with security protections enforced through an Infoblox security policy.  To vi</span>ew the *Security Activity Report*, navigate to the **Reports** section in the Infoblox Portal (**Security** > **Threat Defense** > **Security Activity**). The default *r*eport displays a bar chart showing the distribution of malicious hits throughout your networks over the most recent one-hour time span. The default report also lists detailed information about the respective threats detected at the bottom of the report in the *Events* table.   


![The Security Activity Report page. ](media://515a4b97-7b5b-4e2f-8820-716fc7d102c3)

## Reported Threat Classes and Properties

For information on the threat classes and properties reported, see the *[Infoblox Threat Classification Guide](https://csp.infoblox.com/#/threat_intelligence/resources/threat-classification)** *located in the Infoblox Portal (**Security** > **Research** > **Resources** > **Classification Guide**). <span style="color: #172b4d">To view the full guide without logging into the Infoblox Portal, see </span>*[Infoblox Threat Classification Guide](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/785580419)*<span style="color: #172b4d">. </span>

> ⚠️ **NOTE**: Hover over the question mark icon on any of the report tabs to learn what data id is displayed within the report.

## <span style="color: #000000">Search Tool</span>

<span style="color: #000000">The Search Tool is located above the </span><span style="color: #000000">**Requests**</span><span style="color: #000000"> chart on the top, left-hand side of the page. The search data is pulled directly from the server  To use the search tool paste or type in your search terms into  the search field box. Alternatively, by clicking in the search field and typing the first few letters of your search query an option menu listing popular search terms will be displayed. A power search feature utilizing a new, powerful search query language is also supported.</span>

## <span style="color: #000000">Performing Search Queries</span>

<span style="color: #000000"> Using the search query language, you can search all records with customized queries. By clicking the</span>> Macro (inline-media-image)

<span style="color: #000000">icon located next to the search box, the </span><span style="color: #000000">**Query Syntax**</span><span style="color: #000000"> resource window will appear. You can view sample search queries using the new search query syntax as provided in the tool-tip. Using the sample queries provided, you can construct your own queries to better assist in your searches. Refer to the specific sub-report to view the specific search queries applicable for that report.</span>

## <span style="color: #000000">Traffic Reports by Type</span>

<span style="color: #000000">At the top action bar, you can view security activity traffic interacting with Infoblox policy engines. The security activity traffic reports includes the total number of </span><span style="color: #000000">**Security Events **</span><span style="color: #000000">(inclusive of all reports), </span><span style="color: #000000">**DNS Firewall**</span><span style="color: #000000">, (data including Server, DFP, RPZ), </span><span style="color: #000000">**Web Content**</span><span style="color: #000000">, (traffic filtering by specific categories),  </span><span style="color: #000000">**Threat Insight**</span><span style="color: #000000"> (including data exfiltration, activity, with device and users as pivots with user views) , </span><span style="color: #000000">**Devices (**</span><span style="color: #000000">devices/assets on the network), </span><span style="color: #000000">**Users**</span><span style="color: #000000"> (user names when detected), and information on the </span><span style="color: #000000">**Source**</span><span style="color: #000000"> of reported traffic in your infrastructure. You can also get specific data associated with any one of these security activity report traffic types by clicking on its respective link.  When you click a link, the corresponding overlay chart for the specific type of security activity report is displayed. For example, when you click </span><span style="color: #000000">**Security Events**</span><span style="color: #000000">, a chart depicting each security event will be displayed, providing you with insight into the detected security events. This information can help you identify the top security events within your networks so you can take appropriate corrective actions. Note that the total number for these fields stay the same regardless of the filtering criteria you have configured for the report</span>.

## <span style="color: #000000">Time and Date Filtering</span>

<span style="color: #000000">Clicking </span><span style="color: #000000">**Show**</span><span style="color: #000000">, located to the right-hand side of the page below the top Action bar, allows filtering of records by both time and date. The time period displayed can be modified from 1 hour to 1 month. Optionally, by selecting </span><span style="color: #000000">**Custom**</span><span style="color: #000000"> and choosing </span><span style="color: #000000">*From*</span><span style="color: #000000"> and </span><span style="color: #000000">*To*</span><span style="color: #000000"> values, a custom time period can be chosen. Filtering is limited to 100 responses at a time. You can select a different time frame from the </span><span style="color: #000000">**Show **</span><span style="color: #000000">drop-down menu. </span><span style="color: #000000">**Show**</span><span style="color: #000000"> options include the following: </span>

- <span style="color: #000000">1 hour</span>
- <span style="color: #000000">24 hours (default) </span>
- <span style="color: #000000">48 hours</span>
- <span style="color: #000000">7 days</span>
- <span style="color: #000000">1 month</span>
- <span style="color: #000000">Custom (limited to 31 days of data)</span>

<span style="color: #000000">When </span><span style="color: #000000">**Custom**</span><span style="color: #000000"> is selected, the following date/time filters appear, allowing further customizing of the respective date and time.</span>

- <span style="color: #000000">**From**</span><span style="color: #000000">: When selected a time dial and calendar appears where a time and date can be selected for the start time/date.</span>
- <span style="color: #000000">**To**</span><span style="color: #000000">: When selected a time dial and calendar appears where a time and date can be selected for the end time/date. </span>

## <span style="color: #000000">Records Refresh</span>

<span style="color: #000000">Clicking the refresh icon located to the left of the time/date filtering tool, allows you to refresh the records on the page without refreshing and reloading the entire page and losing your in-place filters.</span>

## <span style="color: #000000">Charts</span>

<span style="color: #000000">The chart displays all data collected for a specific security activity event type. Information in the Requests Chart will reflect the type of activity type selected, along with the  number of events detected during the span of time indicated in the chart. Each green-colored bar on the chart corresponds to a specific time interval within the chosen time span displayed. By rolling over each bar, the number of events, the time interval, and the date of the bar are displayed in a tool-tip window. </span>

## <span style="color: #000000">Table</span>

<span style="color: #000000">The table, located below the chart displays data collected for the selected security activity event type. The default layout is automatically loaded for viewing: however, the table can be customized by adding additional types of report information. To add additional information to a table, clickthe expandable menu icon to </span>select and display from the other additional information types listed in the option window.  By default, events are displayed in chronological order based on information contained within the  **Detected** column. Each of the columns can be sorted or reverse-sorted by clicking on the header label for the column.  

<span style="color: #000000">Located in the bottom-left corner of the table, the total number of table records is displayed. For instance, if there are 984 records available when unfiltered, then the table will display the following: </span><span style="color: #000000">**Showing 984 of 984**</span><span style="color: #000000">. If only 143 records are available after applying filters,  then the table will display the following: </span><span style="color: #000000">**Showing 143 of 984**</span><span style="color: #000000">. The maximum number of records the UI can display is 10,000. Located in the bottom-right corner of the table the number of pages of records is listed. You can click on a page link to view the records for that page.</span>

## <span style="color: #000000">Records Export</span>

<span style="color: #000000">Click </span><span style="color: #000000">**Export**</span><span style="color: #000000"> to export report data in csv format. Based on report type, the maximum number of records available for export varies.  Refer to the table below to view maximum number of records available for export based on report type.</span>

| **Report Type** | **Maximum Number of Records Available for Export** |
| --- | --- |
| Security Events | 50,000 |
| DNS Firewall | 50,000 |
| Web Content | 50,000 |
| Threat Insight | 10,000 |
| Threat View | 10,000 |
| Source | 10,000 |
| Devices | 10,000 |
| Users | 10,000 |
| Insights | 10,000 |

## <span style="color: #000000">Event Details Panel</span>

<span style="color: #000000">The event details panel is located on the right-hand side of the </span><span style="color: #000000">*Requests*</span><span style="color: #000000"> table. The event details panel displays all information associated with a selected security activity event available in the table, but is displayed in a list format. The event details pane is only viewable when there is additional information available that is not posted in the chart.</span>

![The Event Details panel. ](media://f22ec093-3ac3-4edc-ae33-6fa6234a46ec)

## Bypass Code Logging

When a user accesses blocked content using a bypass code, the security report logs the event with the bypass code name. This clearly identifies a user-approved exception rather than a standard allow, enabling SOC teams to treat it appropriately, reduce investigation time, and avoid unnecessary root-cause analysis. Logging details such as the accessed domain and the specific code used also improves tracking and review for security leads and auditors.

![Adding the Bypass Code information (columnar data) to the Security Activity report. ](media://fd1dc6a9-636d-434d-90df-302cb6c84384)

## Security Activity Historical Data Reports

<span style="color: #091e42">Security Activity Historical Data reporting offers the capability to access data that goes back beyond the usual 30-day limit. To access historical data, you can create custom historical data reports by configuring queries and filters according to your organization's specific requirements. These customized reports allow you to obtain the precise historical data you need. It's important to note that saved historical data reports will be retained for a maximum of 30 days, after which they will be automatically deleted from the system.</span>

To navigate to *Security Activity Historical Data *reporting, on the *Security Activity* page, click **Historical Data Viewer **located in the top, right-hand corner of the Security Activity report page.  

For information on creating and running a historical data report, and viewing the report data, see *[Security Activity Historical Data Report](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/267912835)*.

## <span style="color: #000000">Security Activity Report Descriptions</span>

<span style="color: #000000">The following </span><span style="color: #000000">*Security Activity Report*</span><span style="color: #000000"> tab descriptions provide more details specific to each report type:</span>

- *[Security Events](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35406000)*
- *[DNS Firewall](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35437662)*
- *[Web Content](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35406046)*
- *[Threat Insight](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35375296)*
- *[Threat View](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35406075)*
- *[Insights](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35375358)*
- *[Devices](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35375333)*
- *[Users](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35406094)*
- *[Source ](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/39651582)** *