Manage reports
Create, customize, and schedule Cortex XSOAR 8 SaaS reports.
You can create and edit reports in the Reports tab, including adding widgets, scheduling times, setting incident time range, adding recipients, and changing the format and size. Reports support PDF and CSV.
Report actions
You can do the following with reports.
Create or edit a report
When creating a report, what you see is what you get. How you configure the report is how it generates. You can add widgets to a report, change the format and paper size, and insert page breaks by adding the Page Break widget. If you have a table widget that contains many rows, you can select the number of rows on each page or print the whole table (in the table widget, right click and select Force Print full Chart).
You can add your own logo by going to Settings & Info → Settings → System → Server Settings → Logo Configuration and uploading your logo in the Full-size logo field. Reports are generated in PDF or CSV formats.
Create a report from a dashboard
You can create a report from the dashboard as is, or add new widgets as required. You have the same functionality as custom reports, such as format, when to run, and orientation. To create a report from the dashboard, on the Dashboards page click
and select Create report.
Schedule a report
You can schedule a report to run specific times, or run the report immediately. You can also send the report to specific recipients, and restrict the report according to roles.
Generate an out-of-the-box report
Cortex XSOAR comes with out-of-the-box reports, such as critical and high incidents, daily incidents, and last 7 days incidents. You can change the time range for the incidents, the scheduled time and who can receive the report. If you want to make more comprehensive changes to out-of-the-box reports, copy or download (and then upload) the report.
Schedule a report from an incident
Captures investigation-specific data and shares it with team members. You can customize how the information is displayed for existing incidents.
Report scheduling examples
The following examples describe how to schedule a report using the Cron scheduler format. The Cron time string format consists of five fields that Cron converts into a time interval. For example, a Cron string of 0 10 15 * * runs a report on the 15th of each month at 10:00 am.
Last updated
Was this helpful?
