Skip to main content
User guide

Reports

Daily / weekly / monthly SOC operations summaries, a seven-section incident report, archive, Markdown export, push to Feishu or open a ticket.

Operations reports

Generate a summary for a period (day / week / month, or a custom range) from this instance's own data:

SectionSource
Executive summaryThe model's summary of the sections below (paid engine; without a licence only the tables appear)
Alert postureAlert index: totals, by severity, top rules / subjects (enriched with names and criticality from the Asset inventory)
InvestigationsInvestigation / triage / explanation counts and severity split in the period
TriageClusters, likely false-positive share
BaselineLatest patrol score and failed checks
Audit and usageAI calls, success rate, tokens, top indexes
Platform healthCheck-up verdict

Report

Generated reports join the archive (KV copilot_reports; custom ranges are not archived) for review, Markdown download and "Push to Feishu" (an alert card through Outbound channels). Scheduled generation is set under "Schedule" on the channels page (hour, time zone).

Archive

Incident report

After an investigation, "Generate incident report" produces a seven-section Markdown document (overview, blast radius, timeline, attack chain, evidence, recommended actions, open items) for download, push to a channel, or "Open ticket" as the ServiceNow / Jira body. The incident report itself needs no licence, but the investigation it draws on does.

Notes

  • Time windows in report SPL are passed to Splunk as %m/%d/%Y:%H:%M:%S in the splunkd process time zone; a searching user with another zone sees an offset.
  • "Top indexes" counts only calls whose audit event recorded index=.

On this page