Detection reports
The Detection reports module lets you view high-level detection data and pivot to the Investigate module to view low-level data. There are three types of reports.
- Custom reports: Reports that have been manually created by specifying search queries to filter the data by.
- Policy groups: Reports that have been automatically created for existing policy groups.
- Flagged labels: Reports that have been automatically created for entities that have been assigned flagged labels.
Detections are plotted by time in interactive bar graphs which allow you to filter all reports by the time range of a bar or view a breakdown of the number of detections by severity. You can view detailed information about each graph by pivoting to the Investigate module's Detection event stream, where you can drill extensively into individual detections that comprise the report.
You can use this functionality to measure threat risk, implement new security strategies, and ensure success. For example, a commonly breached policy could highlight cyber hygiene training gaps. After strengthening this part of your corporate security training program and further educating users, you could track their progress by verifying that policy violations decrease.