You can create a new report with a choice of data source, presentation and filter.
Navigate to Analysis → Event Reporting → Custom Reports. Click New.
You need to select the data sources for the report. Data source represent the database tables from where information is retrieved to generate the report. The following are the options for data source: Alert Data, Application Data, Endpoint Data, and Performance data.
Click Next to set the display options for the report. Report can be displayed as a Table, Bar Chart, or Pie Chart.
Click Next.
Select the columns of choice that you want to include in the report output by selecting rows in the left panel.
Click Next.
Select a row in the left panel to view the Data Filter options.
You can enhance the filter options for the fields selected in step 4 from the Available Fields options. Use the > and < options to add or remove conditions.
Note
The admin domain selected in the left pane has no impact on the reports generated. The admin domain data filter selected is explicitly to filter the reports that are generated.
When you finish the selections, you can save your report query using Save As.
In the Save Report page, you need to enter a Name and Description for the Query.
You can also select the following options in the Save Query:
Automate Report Generation
Report Frequency
Select events to display
Report Format
Click Finish to save the query.
The report is saved and displayed in the Saved Reports section of the Custom Reports page.
Select the report, and then click Run to view the Run Query.
In the Run Query, enter the Data Options and the Report Format.
Click Run, to run the report query. The generated report is displayed in the selected report format.
When the Bar Chart display option is selected, the output contains both the bar chart and table. If you select the Pie Chart option, the Pie Chart and the table are displayed. If there are no alerts, only the table is displayed.
Data Display Order:
Table Type
Bar Chart
Pie Chart
Table Only
Alert information table
Data is displayed in descending order
Data is displayed in descending order
Data is displayed in ascending order
Once the Custom user defined Report is saved, you cannot change its data source.
Note
In the case of Host Event Table all table information (only table/table with bar chart/ table with pie chart) is displayed in an ascending order.