• Get started with Security Cloud Control Firewall Management
  • How To Request a Security Cloud Control Tenant
  • Sign in to Security Cloud Control
  • Manage Tenants and Users
  • Onboard devices in Security Cloud Control Firewall Management
  • Manage Firewall administration in Security Cloud Control Firewall Management
  • Onboard devices in Security Cloud Control Firewall Management
  • Manage objects
  • About Dynamic Attributes Connector
  • Configure the Dynamic Attributes Connector
  • Dynamic firewall
  • Use Dynamic Objects in Access Control Policies
  • Troubleshoot the Dynamic Attributes Connector
  • Onboard Secure Firewall ASA
  • Configure Secure Firewall ASA
  • Secure Firewall ASA Security Policy Management
  • Monitor Secure Firewall ASA Events
  • Monitor device health metrics
  • Use Cisco Secure Cloud Analytics Portal
  • Upgrade Secure Firewall ASA
  • Troubleshoot Secure Firewall ASA
  • Onboard a Firewall Threat Defense Device
  • Migrate Threat Defense to Cloud-Delivered Firewall Management Center
  • Configure Cloud-Delivered Firewall Management Center-Managed Secure Firewall Threat Defense
  • Introduction to AgenticOps insights
  • Introduction to Agent Workforce
  • Monitor Cloud-Delivered Firewall Management Center-Managed Threat Defense Device Events
  • FTD Dashboard
  • Analyze and Remediate Security Policy Anomalies with Policy Analyzer and Optimizer
  • Integrate Catalyst SD-WAN Manager with Security Cloud Control
  • Onboard Catalyst SD-WAN Manager
  • Configure Next-Generation Firewall Capabilities of Catalyst SD-WAN Manager
  • Monitor Catalyst SD-WAN Events
  • Onboard an On-Premises Firewall Management Center
  • Configure On-Premises Firewall Management Center-Managed Threat Defense Devices
  • Onboard an Umbrella Organization
  • Configure an Umbrella Organization
  • Onboard Cisco Meraki MX devices
  • Configure Cisco Meraki
  • Onboard AWS VPC
  • Configure AWS VPC
  • Onboard Cisco IOS Devices
  • Configure Cisco IOS
  • Onboard an SSH Device
  • Configure SSH Devices
  • Establish Site-to-Site VPN connection using Security Cloud Control Firewall Management
  • Establish Remote Access VPN connection using Security Cloud Control Firewall Management
  • Configure Firewall for Universal Zero Trust Network Access
  • Manage device configuration
  • Manage onboarded device settings
  • Use the Security Cloud Control Command Line Interface Tool (CLI)
  • Manage CLI Templates
  • Migrate Firewalls with the Migration Tool in Security Cloud Control
  • Events in Security Cloud Control
  • Security Analytics and Logging Licenses
  • Secure Event Connectors
  • Monitor Catalyst SD-WAN Events
  • View Events in Security Cloud Control Firewall Management
    • View live events
    • View historical events
    • Customize the events view
    • Show and hide columns on the event logging page
    • Change the time zone for the event timestamps
    • Customizable event filters
    • Search and filter events using the event logging page
      • Filter Live or Historical Events
      • Filter Only NetFlow Events
      • Filter for ASA or FDM-Managed Device Syslog Events but not ASA NetFlow Events
      • Combine Filter Elements
      • Search Events Using the Events Logging Page
        • Use Sample Filters to Search Events
        • Search Historical Events in the Background
          • Schedule to Generate a Search Report in the Background
          • Download a Search Report
    • Event attributes in Security Analytics and Logging
  • Use Cisco Secure Cloud Analytics Portal
  • Monitor Remote Access Virtual Private Network Sessions from Secure Firewall ASA and Firewall Threat Defense
  • Monitor and report change logs, workflows, and jobs
  • Smart Licensing Dashboard
  • Troubleshooting
  • FAQ and support
  • Security and Internet Access
  • Terraform
  • Open Source and 3rd Party License Attribution
  • Cisco AI Assistant User Guide

Schedule to Generate a Search Report in the Background

Use the Report feature in the Event Logging page to run one-time or scheduled event log searches in the background and generate reports. You can modify or cancel the scheduled report at any time. You can also modify a one-time search query to be a recurring search.

Note
  • You can schedule to generate reports only for historical events.

  • You can opt to get alerts on reports that have started, completed, or have failed.

Follow these steps to schedule a search and generate report:

Procedure


Step 1

In the navigation bar, choose Events & Logs > Events > Event Logging.

Step 2

Click the Historical tab to view historical events.

Step 3

Type the search query in the search bar.

Step 4

Click the Search drop-down and choose Schedule Report.

Step 5

(Optional) Enter a name for the report to identify it.

Step 6

The Generate report now check box is checked by default. When checked, the report generation starts upon saving.

Step 7

Check the Setup recurring schedule check box and configure these settings:

  • Search Logs for the Last: Specify how far back you want to search through.

  • Frequency: Specify how frequent you want the scheduled search to occur and the time at which you want it to run.

Step 8

Confirm the scheduled search criteria at the bottom of the window. Click Schedule and Generate Now. If you did not opt for the search to start immediately, click Schedule Report.

Scheduled search reports are available to view for up to seven days before Security Cloud Control automatically deletes them.


Copyright © 2026, Cisco Systems, Inc. All rights reserved.