Generate the SaaS Application Usage Report
Focus
Focus
Next-Generation Firewall

Generate the SaaS Application Usage Report

Table of Contents

Generate the SaaS Application Usage Report

  1. Tag applications that you approve for use on your network as Sanctioned.
    For generating an accurate and informative report, you need to tag the sanctioned applications consistently across firewalls with multiple virtual systems, and across firewalls that belong to a device group on Panorama. If the same application is tagged as sanctioned in one virtual system and is not sanctioned in another or, on Panorama, if an application is unsanctioned in a parent device group but is tagged as sanctioned in a child device group (or vice versa), the SaaS Application Usage report will report the application as partially sanctioned and will have overlapping results.
    Example: If Box is sanctioned on vsys1 and Google Drive is sanctioned on vsys2, Google Drive users in vsys1 will be counted as users of an unsanctioned SaaS application and Box users in vsys2 will be counted as users of an unsanctioned SaaS application. The key finding in the report will highlight that a total of two unique SaaS applications are discovered on the network with two sanctioned applications and two unsanctioned applications.
    1. Select ObjectsApplications.
    2. Click the application Name to edit an application and select Edit in the Tag section.
    3. Select Sanctioned from the Tags drop-down.
      You must use the predefined Sanctioned tag (
      ). If you use any other tag to indicate that you sanctioned an application, the firewall will fail to recognize the tag and the report will be inaccurate.
    4. Click OK and Close to exit all open dialogs.
  2. Configure the SaaS Application Usage report.
    1. Select MonitorPDF ReportsSaaS Application Usage.
    2. Click Add, enter a Name, and select a Time Period for the report (default is Last 7 Days).
      By default, the report includes detailed information on the top SaaS and non-SaaS application subcategories, which can make the report large by page count and file size. Clear the Include detailed application category information in report check box if you want to reduce the file size and restrict the page count to 10 pages.
    3. Select whether you want the report to Include logs from:
      In PAN-OS 10.0.2 and later releases, reports generated from logs in the Strata Logging Service only support including logs from the Selected Zone.
      • All User Groups and Zones—The report includes data on all security zones and user groups available in the logs.
        If you want to include specific user groups in the report, select Include user group information in the report and click the manage groups link to select the groups you want to include. You must add between one and up to a maximum of 25 user groups, so that the firewall or Panorama can filter the logs for the selected user groups. If you do select the groups to include, the report will aggregate all user groups in to one group called Others.
      • Selected Zone—The report filters data for the specified security zone, and includes data on that zone only.
        If you want to include specific user groups in the report, select Include user group information in the report and click the manage groups for selected zone link to select the user groups within this zone that you want to include in the report. You must add between one and up to a maximum of 25 user groups, so that the firewall or Panorama can filter the logs for the selected user groups within the security zone. If you do select the groups to include, the report will aggregate all user groups in to one group called Others.
      • Selected User Group—The report filters data for the specified user group only, and includes SaaS application usage information for the selected user group only.
    4. Select whether you want to include all the application subcategories in the report (the default) or Limit the max subcategories in the report to the top 10, 15, 20 or 25 categories (default is all subcategories).
    5. Click Run Now to generate the report on-demand for the last 7-day and the last 30-day time period. Make sure that the pop-up blocker is disabled on your browser because the report opens in a new tab.
    6. Click OK to save your changes.
  3. Schedule Reports for Email Delivery.
    The last 90-days report must be scheduled for email delivery.
    On the PA-220R and the PA-800 Series firewalls, the SaaS Application Usage report is not sent as a PDF attachment in the email. Instead, the email includes a link that you must click to open the report in a web browser.