Reports, email schedules, and health assessment
Produce useful operational and security reports, customize their format, and schedule email delivery without confusing raw events with incidents.
Not rated yet
The default report answers three administrator questions first:
- Is the server and protection stack operating normally?
- What failures or unresolved conditions need action?
- Is there evidence of attack, exploitation, or an unauthorized file change?
Executive first page
The first page should show the reporting period, DNN and DNN Defender versions, edition/license,
overall health, protection modes, baseline state, last successful scans, open Critical/High items,
blocked versus observed WAF activity, integrity changes, operational errors, and the three most
important recommended actions. It must distinguish No evidence observed from Evidence that
the site was not attacked—the second statement cannot be supported by monitoring alone.
Detailed sections
- control health and data freshness;
- confirmed or suspected incidents with status and owner;
- WAF threat signals with action and correlation context;
- malware/realtime findings with engine evidence;
- FIM Added/Modified/Deleted changes and recovery availability;
- DNN advisory exposure and compensating-control state;
- operational errors grouped by root cause instead of repeated identical rows;
- remediation priorities, target dates, and validation steps.
Assessment basis
The report identifies its observation period, enabled controls, evidence freshness, and missing
sources. It may map findings to NIST, OWASP or CVSS concepts; the mapping and its limits are
explained in Standards and evidence scope.
Scheduling and templates
Use Reports to edit the approved header, executive summary, sections, branding, recipients,
subject, cadence, and server-time schedule. Preview the rendered report and send a test message
before enabling recurrence. Keep dynamic HTML out of the email subject; the subject should contain
plain text such as severity, site, period, and report type.
Recommended cadence is daily for high-risk internet-facing sites and weekly for stable sites, with
immediate alerts reserved for Critical findings and control failures. Avoid flooding recipients
with identical events; use correlation and deduplication while keeping the underlying audit data.
Was this page helpful?