Managing and viewing reports | SecurityHub

  • Updated

Applies to: Global Org Admins, IT Admins and Compliance Admins
 

Security and compliance reports are generated by a schedule. You create a schedule to run at a certain time and at certain intervals. When a report is generated and notification email is sent to the schedule creator and the Global Org Admins. The reports can be viewed and downloaded on the Exports tab.

Icons_Approved.svg Events that are included in the event log

The Event Log displays events that were triggered on the Intralinks platform. Set filters to select the events you want to view. Event logging started January 1, 2024. Up to two years of events can be displayed beginning in 2026.

Identity and Access Management events

  • Geo Blocking: A Geo blocking rule prevented a user's login based on the user's location.
  • Identity Switch: A user switched from their primary account (the account used to authenticate successfully into the Intralinks platform) to an Identity+ group account that they are authorized to use. This event is also triggered when the user switches back from the Identity+ group account to their primary user account.
  • IP Blocking: An IP blocking rule prevented a user's login based on the user's IP address.
  • Login: A user successfully logged into the Intralinks platform.
  • Logout: A user successfully logged out of the Intralinks platform, or the user's Intralinks session times out due to user inactivity.
  • User Created: A user account/profile was created on the Intralinks platform.

Authentication events

These events are only available on domains not using SSO.

  • API Login Attempt: A user entered a password through an API call.
  • Factor Challenge: A user responded to a factor challenge over email, push notification, TOTP or SMS.
  • Login Attempt: A user entered a password through a browser. MFA may be triggered as part of the standard login process, based on adaptive authentication.
  • MFA Recovery Factor Reset: A user successfully reset all the MFA recovery factors.
  • Password Reset: A user set a new password.

VDRPro events

  • Container Access: The user logged in to VDRPro and entered a VDR.
  • Document Created: The user created a document.
  • Document Deleted: The user deleted a document.
  • Document Updated: The user updated a document.
  • Folder Created: The user created a folder.
  • Folder Deleted: The user deleted a folder.
  • Folder Updated: The user updated a folder.

VIA Pro events

  • Container Access: The user logged in to VIA Pro and entered a Workspace.
  • Document Created: The user created a document.
  • Document Deleted: The user deleted a document.
  • Document Updated: The user updated a document.
  • Folder Created: The user created a folder.
  • Folder Deleted: The user deleted a folder.
  • Folder Updated: The user updated a folder.

DealCentre AI events

Folder events and deal access

  • Container Access: The user logged in to DealCentre AI and accessed a deal.
  • Folder Upload: The user uploaded a folder.
  • Folder Duplicate: The user created a copy of a folder.
  • Folder View - The user viewed a folder
  • Folder Rename: The user renamed a folder.
  • Folder Restore The user restored a previously deleted folder
  • Folder Delete - The user deleted a folder. The folder can be restored by the user.
  • Folder Permanent Delete - The user permanently deleted a folder.
  • Folder Download - The user downloaded a folder.

Document events

  • Document Upload - The user uploaded a document.
  • Document Duplicate - The user created a copy of the document.
  • Document View - The user viewed a document.
  • Document Rename - The user renamed a document.
  • Document Restore - The user restored a previously deleted document.
  • Document Replace - The user replaced an existing document with a new version.
  • Document Delete - The user deleted a document. The document can be restored by user.
  • Document Permanent Delete - The user permanently deleted a document.
  • Document Download - The user downloaded a document.
  • Document Bulk Download - The user downloaded multiple documents at once. Also triggered for each document within a folder when a user performs a Folder Download.
  • Document Redacted - The user applied redactions to a document.
  • Document Redaction Removed - The user removed redactions from a document.

Icons_Approved.svg How to create and manage schedules

Create a schedule

After a schedule is created only you and Global Org Admins can edit or remove the schedule. When an report is exported, both you and the Global Org Admins are notified by email. The reports will then be available on the Exports tab for download.

Activity Reports 

Activity Reports are available for VDRPro, VIAPro and DealCentre AI.

  1. Click the Reports tab.
  2. Click Schedules.
  3. Click Create Schedule.
  4. Step 1: Choose a Report. Select Activity Reports.
  5. Step 2: Time. Set start and end dates for the recurrence. In the Repeats field, click the frequency you want the report to repeat, and select the time to generate the report. Click Next.
  6. Step 3: Filters. Select the domains, applications, events, login locations and user statuses that you want included in the report. Each field defaults to All. Click Next.
  7. Step 4: Format. Select the format as CSV or Excel. Depending on your contract type, you can select a destination for the reports to be delivered outside of SecurityHub in the File Exporter dropdown. The selection will be blank if you do not have the service configured and the report will be saved in the Exports tab. Click Next.
  8. Step 5: Name. In the Schedule Name field enter a name for the report. 
  9. Click Create.

Entitlements Report

Entitlements report is only available for DealCentre AI.

  1. Click the Reports tab.
  2. Click Schedules.
  3. Click Create Schedule.
  4. Step 1: Choose a Report. Select Entitlements Report.
  5. Step 2: Time. Set start and end dates for the recurrence. In the Repeats field, click the frequency you want the report to repeat, and select the time to generate the report. Click Next.
  6. Step 3: Filters. Under Report Coverage, select the domains or specific users. 
    • If you select Domains, use the Domains dropdown to select all domains or specific ones or if you choose Specific Users, provide the email ids of the users in the Selected Users textbox.
    • In the Applications field, select the applications the report covers. DealCentre AI is added by default.
    • Click Next.
  7. Step 4: Format. Select the format as CSV or Excel. Depending on your contract type, you can select a destination for the reports to be delivered outside of SecurityHub in the File Exporter dropdown. The selection will be blank if you do not have the service configured and the report will be saved in the Exports tab. Click Next.
  8. Step 5: Name. In the Schedule Name field enter a name for the report. 
  9. Click Create.

Electronic Communications (E-Comms) Report

Electronic communications report is only available for DealCentre AI.

  1. Click the Reports tab.
  2. Click Schedules.
  3. Click Create Schedule.
  4. Step 1: Choose a Report. Select Electronic Communications Report.
  5. Step 2: Time. Set start and end dates for the recurrence. In the Repeats field, click the frequency you want the report to repeat, and select the time to generate the report. Click Next.
  6. Step 3: Filters. Under Report Coverage, select the domains or specific users. 
    1. If you select Domains, use the Domains dropdown to select all domains or specific ones or if you choose Specific Users, provide the email ids of the users in the Selected Users textbox.
    2. In the Applications field, select the applications the report covers. DealCentre AI is added by default.
    3. In the Events field, select the events that you want the report to include.
    4. Click Next.
  7. Step 4: Format. Select the format as TXT, XML or JSON. Depending on your contract type, you can select a destination for the reports to be delivered outside of SecurityHub in the File Exporter dropdown. The selection will be blank if you do not have the service configured and the report will be saved in the Exports tab. Click Next.
  8. Step 5: Name. In the Schedule Name field enter a name for the report. 
  9. Click Create.

Note: File Exporter is an optional service available in SecurityHub Pro contracts and is configured by Intralinks Services. If you would like to know more about the File Exporter service and how to request it, contact your Sales Representative or your Customer Success Manager. If you are unsure who your contacts are, email IL-SH-Support@sscinc.com

Activate the schedule

After you create a schedule, it appears in the Schedules grid with the state set to Setup. You need to activate it.

  1. Click the Reports tab.
  2. Click Schedules.
  3. From the Active column for the newly created schedule, select the toggle.
  4. In the Update Schedule State window, select Active from the State dropdown.
  5. Select Save.

 

Note: Once the schedule is active, it will run automatically at the selected frequency. 

Run a report immediately

To generate a scheduled report immediately, you can use the Run Now option. 

  1. Click the Reports tab.
  2. Click Schedules.
  3. Scroll to the right and in the Actions field of the report you want to run, click the Run Now icon.

Note: Running a report immediately will not edit or remove the upcoming scheduled report. It will immediately generate the report using the already set domains, events and user statuses from the set cadence up to the past one hour. 

Edit a schedule

Only the user that created the report or a Global Org Admin can edit a schedule.

  1. Click the Reports tab.
  2. Click Schedules.
  3. Scroll to the right and in the Actions field of the report you want to run, click the Edit icon.
  4. Make any changes to the time to generate the report and to the format in which you want to generate the report. 
  5. Click Save.

Delete a schedule

Only the user that created the report or a Global Org Admin can delete a schedule.

  1. Click the Reports tab.
  2. Click Schedules.
  3. Scroll to the right and in the Actions field of the report you want to run, click the Remove icon.
  4. Click Remove to confirm

Icons_Approved.svg How to view and download reports

View and download scheduled reports

After a schedule report is generated, you can download it.

  1. Click the Reports tab.
  2. Click Exports.
  3. To download a report, scroll to the right and click the Download icon in the row of the report you want to download.

View and export event logs

  1. Click the Reports tab.
  2. Click Event Log.
  3. (Optional.) To filter the event log, click Filters. Select the date range and the events you want to include and click Apply.

    Note: The resource name for VDRPro and VIA Pro events can be the name of the VDR, Workspace, or document.

  4. (Optional.) To export the event log, click Export. Enter a name for the exported file and the format in which to export it and click Export. After the file is generated, you can download it from the Exports tab.

 

Was this article helpful?