Downloading data for events and devices

RocketCyber focuses on the Security Operations Center (SOC) to review events and create incidents for items that require your attention. However, there may be times when you need to download certain elements from the user interface.

The CSV/JSON download feature allows you to perform filtered queries against datasets and export the resulting data in either CSV or JSON format.

The download feature is available in the following locations:

  • The “triage view” of each app on the dashboard (the view obtained after clicking Review to see the events for each app)

  • The Agents page

  • The Firewalls page

  • The Incidents page

  • The Suppression Rules page

After you request a download, you will see a message indicating that an email has been sent to you.

You will receive the requested dataset as downloadable links in an email sent to the address you are currently logged in with. The links will be valid for one hour after the email is sent.

Important information about this feature

  • Large downloads will be divided into separate files to improve response times.

  • By default, only 35 days of data are displayed and can be downloaded in the Events view. If you wish to download a wider date range, add the Detection Date filter in the Events view, select + Add Filter, and then click Search.

    NOTE  After adding a filter, the download button will be grayed out until you click Search to ensure the query returns data.

  • There may be instances where no data is displayed in the UI (e.g., if the date range does not cover the last 35 days), but the download may still contain the requested data.
  • If no data is available for your query, the email body will read, “No results were found in the requested export. Please adjust your filters and try again.”

  • Event data downloads are compressed and delivered in GZ format, and these files will need to be extracted to view. Tools like 7-Zip can extract these files on Windows.

Please ensure that no-reply@rocketcyber.com is allowed in your email protection solution to ensure receipt of download emails.