Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Create Log Streaming Report Definitions

You can create a log stream report to view the data (bytes) transferred to the SIEM system, such as Microsoft Sentinel. You can create a report for the current month, previous month, or the entire period of data transfer. The report contains the log stream name, the type of log forwarded (audit log, sessions log, or security events), and the number of bytes forwarded to the external SIEM system.

Before You Begin

To configure a log stream report:
  1. Select Monitor > Reports > Report Definitions.
  2. Click Create, and select Log Streaming Report.
    The Create Log Streaming Report Definition page is displayed.
  3. Complete the configuration according to the guidelines provided in Table 1.
    Table 1: Log Streaming Report Definition

    Settings

    Guidelines

    General

    Report Name

    Enter a unique string for the report name containing maximum 64 alphanumeric characters. The name can contain dashes.

    Description

    Enter a description containing maximum 900 characters for the report.

    Content

    Report Type

    Select from the following options:
    • Current Month Usage—Generate the report for current month till date

    • Last Month Usage—Generate the report for the previous month

    • Historical Usage—Generate the report about the entire period of data transfer except current month to the SIEM system.

    Schedule

    Report Schedule

    Click Add Schedule.

    Select the type of report schedule to use:

    • Run now—Schedule and publish the configuration at the current time.

    • Schedule at a later time—Schedule and publish the configuration at a later time.

    Email Section

    Email Recipients

    Enable this option to send the report to specific recipients in an email.

    • Recipients—Enter or select the e‐mail addresses of the recipients. You can search e-mail addresses of users by their first name. You can also enter external email addresses.

    • Subject—Enter the subject for the e‐mail notification.

    • Comments—Enter the comments for the e‐mail notification.

  4. Click OK to save the report definition.

A new log streaming report definition with the defined configurations is created.