Generating and exporting reports
Only users with user admin permissions in Barracuda Cloud Control can view the Reports page.
If you want to generate a recurring report on a schedule, see Scheduling Reports.
BarracudaONE’s Value Report differentiates between threats intercepted before delivery and after delivery to user inboxes.
| Threats intercepted before delivery to user inboxes | Threats intercepted after delivery to user inboxes |
Intercepted by | Barracuda Email Gateway Defense (EGD) | Barracuda Impersonation Protection (IP) Barracuda Incident Response (IR) (IP and IR are now also known as Barracuda Integrated Email Protection) |
Examples | Spam, known malware, hygiene, and volumetric threat control | Delayed phishing, business email compromise (BEC), account takeover (ATO), and automated remediation |
Conforms to | Gartner’s 2021 Email Security Market Secure Email Gateway (SEG) definition | Gartner’s 2021 Email Security Market API‑based Integrated Cloud Email Security (ICES) definition |
Use value reports to show the advantages of your protection. These reports itemize the threats that your services have blocked, showing the possible security breaches that you prevented from reaching your clients.
Reports can be generated for a single account only. You can't generate a report that includes multiple accounts.
How elements in reports are generated
The elements in reports are generated from the following Barracuda applications in your environment:
Email Gateway Defense
Incident Response
Impersonation Protection
Cloud Archiving Service
Cloud-to-Cloud Backup
Data Inspector
Barracuda Managed XDR
The items you can include in your report are generated from the applications you have in your environment. For example, if you have Impersonation Protection, you get data on targeted attacks prevented by Impersonation Protection, but if you have both Impersonation Protection and Incident Response, you get data from both sources. Impersonation Protection and Incident Response metrics are now combined under the Integrated Email Protection metrics.
For certain widgets, data for Incident Response and Impersonation Protection (Integrated Email Protection) is only available from March 7, 2025.
Data from Email Gateway Defense is available for the last 365 days.
When you're missing applications
If an element aggregates data from more than one application, but you don't have all the applications the data is aggregated from, the element aggregates data from the applications you do have. For example, the Threats blocked element aggregates data from Email Gateway Defense, Incident Response, and Impersonation Protection. If you only have Email Gateway Defense and Impersonation Protection, the element is generated from those two applications.
If you don't have any of the applications that an element aggregates data from, the element displays blank or "0". You can clear the check boxes of elements that are aggregated from applications you don't have.
Email related |
|
|
Element | Description | How it's generated |
Emails evaluated | The number of emails evaluated by security programs in the selected timeframe. The following data is available:
| Aggregates the total number of:
|
Emails archived | The number of emails that have been archived in the selected timeframe. | The total number of Emails archived by Barracuda Cloud Archiving Service. |
Email volume trend | A graph of the trend of email volume in the selected timeframe.
The following data is available:
| Analyzes the trend from:
|
Total threats blocked | The number of threats blocked in the selected timeframe. The following data is available:
| Aggregates the total number of:
|
Threats remediated after delivery | The number of threats remediated after delivery to the user’s inbox. The following data is available:
| The total number of emails deleted and quarantined by automated remediation/creation of incidents, and automated workflows that resulted in incidents by Integrated Email Protection. |
Inboxes protected | The number of inboxes being protected. | The total number of email inboxes being protected by Integrated Email Protection. |
Threats blocked immediately | The number of threats blocked immediately in the selected timeframe. The following data is available:
| The total number of emails deleted and quarantined by automated remediation/creation of incidents, and automated workflows that resulted in incidents, by Incident Response. |
Incidents investigated | The number of suspected threats investigated in the selected timeframe.
The following data is available:
| The total number of incidents investigated by Incident Response. |
Threat breakdown | A classification of the types of email threats identified before messages arrive and those detected later through continued monitoring. | Compiled from:
|
Top 5 threat types | A list of the most common email threat types in the selected timeframe.
The following data is available:
| Compiled from:
|
Top 5 users exposed to threats | A list of the most common recipients of email threats in the selected timeframe.
The following data is available:
| Complied from:
|
If a Value Report has never been customized, the following widgets under Email Protection are selected by default.
Threats remediated after delivery
Inboxes protected
Threat breakdown
If a Value Report has been customized, these widgets are not selected by default.
Data protection |
|
|
Item | Description | How it's generated |
Violations found | The number of data violations found in the selected timeframe | Compiled from the violations in scans completed by Data Inspector. |
Scans completed | The number of scans completed in the selected timeframe | Compiled from the scans completed by Data Inspector. |
Top violation type | A list of the most common types of data violations in the selected timeframe.
The following data is available:
| Compiled from the violation types in scans completed by Data Inspector. |
Top user with violations | A list of the top users with the most violations in the selected timeframe.
The following data is available:
| Compiled from the user in scans completed by Data Inspector. |
Data size backed up | The amount of data backed up, in terabytes | Compiled from the amount of data backed up by Cloud-to-Cloud Backup. |
Backups by source | The number of backups in the selected timeframe | Compiled from the sources in Cloud-to-Cloud Backup. |
Managed Threat Detection & Response |
|
|
Item | Description | How it's generated |
Devices managed | Number of devices currently monitored. | Compiled from devices monitors by Managed XDR. |
Security alerts | Number of threats identified and reviewed | Complied from total threats identified and reviewed by Managed XDR |
High-severity alerts | Number of high impact, urgent threats detected Percentage of alerts that are high-severity. | Compiled from urgent threats with high impact detected by Managed XDR and the percentage of Managed XDR alerts that are high-severity out of total alerts. |
Mitigated threats | Threats that have been mitigated | Complied from threats mitigated by Managed XDR. |
Automated threat response | Threats have been responded to automatically | Compiled from Managed XDR threats. |
To generate a report
If you're not on the Reports > Report page, click Reports, then click Report.
If you haven't selected an account, click the Account switcher, then select your account.
To choose a time frame for the report, do one of the following:
Select an option in the Time frame box.
Select a date in the Start date box, and select a date in the End date box.
If you want to show logos on the report, select any of the following:
The Display check box next to the Account Logo.
The Display check box next to Your Logo.
Select the check boxes of the email-related items you want to show:
Threats blocked
Emails evaluated
Emails archived
Incidents remediated
Incidents investigated
Email volume trend
Top threat type
Top recipient for threats
Email volume trend
NOTE To include all of the email-related items, select the Email Protection check box.
Select the check boxes of the data protection-related items you want to show:
Data size backed up
Backups by source
Scans completed
Violations found
Top violation type
Top user with violations
NOTE To include all of the email-related items, select the Data Protection check box.
Select the check boxes of the Managed Threat Detection & Response-related items you want to show:
Devices managed
Security alerts
High-severity alerts
Mitigated threats
Automated threat response
Click Save
.
To export a report
Exporting a report generates a .PDF of the report
Generate your report using the To generate a report procedure above.
Click Actions
.
Click Export
.
The report downloads to your Downloads folder.