Reports

Prev Next

Overview

The SAFE platform supports exporting large datasets as CSV reports. Reports are generated asynchronously — once initiated, the report is processed in the background and becomes available for download from the Reports page when ready.

Supported export types:

Export Type

Source Page

Max Rows

Column Selection

Findings Report

Findings Listing

2.5 Million

Findings + Assets

Unique Findings Report

Findings Listing

2.5 Million

Findings columns only

Asset Report

Assets Listing

1 Million

Asset columns

Software Report

Asset Details → Software

250,000

All software columns (fixed)

Findings Report Export

Export findings with associated asset data. You can select columns from both Findings and Assets categories.

  1. Navigate to Findings from the left navigation menu.

  2. Apply any filters to narrow down the findings you want to export (e.g., severity, finding type, CVE ID, status).

  3. Click the Download button (↓) in the top-right area of the listing.

  4. Select Export Findings from the dropdown menu.

  5. In the Export Findings dialog, choose columns from two tabs:

    • Findings tab (54 columns available) — includes Finding Name, Severity, CVE ID, EPSS Score, CISA KEV, etc.

    • Assets tab (38 columns available) — includes Asset Name, Asset Criticality, IP Address, Cloud Region, etc.

  6. Click Download to initiate the export.

  7. A success notification will appear confirming the report is being generated.

  8. Navigate to Reports from the left navigation menu to check the status and download the report once ready.

Findings Column Keys (API Reference)

Display Name

API Column Key

Finding ID

id

Finding Name

findingName

Title

title

Finding Type

findingType

Status

status

First Seen

firstSeen

Last Seen

lastSeen

CVE Published Date

cvePublishDate

CVE ID

cveIds

CWE ID

cweIds

Finding Severity

severity

Finding Score

score

Fix Available

isFixAvailable

CISA KEV

cisaKev

CISA KEV Added Date

cisaAddedDate

CISA KEV Due Date

cisaDueDate

EPSS Score

epss

CVSS v2 Score

cvssV2Score

CVSS v3 Score

cvssV3Score

CVSS v4 Score

cvssV4Score

CVSS v2 Severity

cvssV2Severity

CVSS v3 Severity

cvssV3Severity

CVSS v4 Severity

cvssV4Severity

CVSS v2 Vector

cvssV2Vector

CVSS v3 Vector

cvssV3Vector

CVSS v4 Vector

cvssV4Vector

Asset Criticality

assetCriticality

Compliance Framework

complianceFramework

MITRE ATT&CK Tactic

mitreAttackTactic

MITRE ATT&CK Technique

mitreAttackTechnique

Remediation Actions

remediations

Description

assessmentDescription

Finding Component

componentInstallPath

Asset Count

assetCount

Finding Count

findingCount

Ticketed

ticketed

Onboarding Source

onboardingSource

Contributing Sources

contributingSources

Source Name

sourceName

Mitigation Efficacy

mitigationEfficacy

Policy Name

policyName

Control ID

controlId

Controls

controls

Asset Columns (available in Findings export)

Display Name

API Column Key

Asset Name

assetName

Asset Types

assetTypes

Asset Subtype

assetSubtype

Asset Last Analysed

assetLastAnalysedAt

IP Address

ipAddress

Subnet

subnet

Criticality

criticality

Domain

domain

Serial Number

serialNumber

Hardware ID

hardwareId

Attack Surface

attackSurface

Cloud Resource ID

cloudResourceId

Location

location

Region

region

Cloud Region

cloudRegion

Cloud Provider

cloudProvider

Cloud Instance ID

cloudInstanceId

OS Platform

platform

Zone

zone

Business Owner

businessOwner

VM Owner

vmOwner

IT Owner

itOwner

Device Owner

deviceOwner

Cloud Account ID

cloudAccountID

Cloud Resource Group

cloudResourceGroupName

CPU Model Name

cpuModelName

BIOS Version

biosVersion

BIOS Vendor

biosVendor

BIOS Release Date

biosReleaseDate

Operating System

operatingSystem

OS Vendor

osVendor

OS Version

osVersion

System Manufacturer

systemManufacturer

OS Release Install Date

osReleaseInstallDate

Cloud Service Provider

cloudServiceProvider

Asset Exposure Score

assetExposureScore

Asset Tags

assetTags

Unique Findings Report Export

Export deduplicated findings (one row per unique finding across all assets). Asset columns are not supported in this export type.

  1. Navigate to Findings from the left navigation menu.

  2. Apply any filters to narrow down the findings you want to export.

  3. Click the Download button (↓) in the top-right area of the listing.

  4. Select Export Unique Findings from the dropdown menu.

  5. In the Export Unique Findings dialog, select the findings columns you wish to include. Only finding-level columns are available (asset columns are not applicable for deduplicated findings).

  6. Click Download to initiate the export.

  7. A success notification will appear confirming the report is being generated.

  8. Navigate to Reports from the left navigation menu to check the status and download the report once ready.

Notes

Unique findings are deduplicated by FINDING_ID. For findings that appear on multiple assets, only the instance with the highest exposure score is included.

Asset Report Export

Export asset inventory data directly from the Assets listing page.

  1. Navigate to Assets from the left navigation menu.

  2. Apply any filters to narrow down the assets you want to export (e.g., asset type, criticality, zone, attack surface).

  3. Click the Download button (↓) in the top-right area of the listing.

  4. In the Export Assets dialog, select the columns you wish to include from the available asset columns.

  5. Click Download to initiate the export.

  6. A success notification will appear confirming the report is being generated.

  7. Navigate to Reports from the left navigation menu to check the status and download the report once ready.

Asset Export Column Keys (API Reference)

Display Name

API Column Key

Default

Asset Name

assetName

Yes

Asset Types

assetTypes

Yes

Asset Subtype

assetSubtype

No

Asset Criticality

criticality

Yes

Findings Count

findingCount

Yes

IP Address

ipAddress

Yes

Subnet

subnet

No

Asset Score

assetExposureScore

No

Asset Last Analysed

assetLastAnalysedAt

No

Attack Surface

attackSurface

No

Zone

zone

Yes

OS Platform

platform

Yes

Location

location

No

Serial Number

serialNumber

No

Cloud Unique ID

cloudResourceId

No

Cloud Region

cloudRegion

Yes

Cloud Instance ID

cloudInstanceId

No

Cloud Provider

cloudServiceProvider

Yes

Cloud Account ID

cloudAccountID

Yes

Cloud Resource Group

cloudResourceGroupName

No

Business Owner

businessOwner

No

VM Owner

vmOwner

Yes

IT Owner

itOwner

No

Device Owner

deviceOwner

No

Asset Patch State

devicePatchState

No

OS Patch State

osPatchState

No

EDR Status

edrStatus

No

Hardening Status

hardeningStatus

No

CPU Model Name

cpuModelName

No

BIOS Version

biosVersion

No

BIOS Vendor

biosVendor

No

BIOS Release Date

biosReleaseDate

No

Operating System

operatingSystem

No

OS Vendor

osVendor

No

OS Version

osVersion

No

System Manufacturer

systemManufacturer

No

Image Tag

imageTag

No

OS Release Install Date

osReleaseInstallDate

No

Asset Tags

assetTags

No

Asset First Seen In

assetOnboardingSource

No

Asset Integration

assetContributingSources

No

Asset Source

assetSourceName

No

Software Report Export

Export software inventory for a specific asset. This export includes all software detected on the selected asset with their patch states, categories, and sources.

  1. Navigate to Assets from the left navigation menu.

  2. Click on the asset you want to export software data for. This opens the Asset Details page.

  3. Click the Software tab in the asset details view.

  4. Scroll down to the Software listing table.

  5. Click the Download button (↓) in the top-right area of the software listing.

  6. A success notification will appear confirming the report is being generated.

  7. Navigate to Reports from the left navigation menu to check the status and download the report once ready.

Note

The software export downloads all columns automatically. There is no column selection dialog for this export type. The exported columns include: Software Name, Software Version, Software Vendor Name, Finding Count, Software Patch State, Software Category, Software Sub Category, and Software Source.

Report Export via API

All report exports can also be triggered programmatically using the SAFE REST API. This is useful for automation, scheduled exports, or integration with external systems.

Authentication

The SAFE API uses a two-step authentication process:

Step 1: Obtain an access token

curl -X POST 'https://<TENANT_URL>/api/v3/auth' \
  -u '<USERNAME>:<API_TOKEN>' \
  -H 'Content-Type: application/json'

This returns a JSON response containing an accessToken.

Step 2: Use the access token

Include the token as a Bearer token in all subsequent API requests:

Authorization: Bearer <ACCESS_TOKEN>

Create Report (POST /api/v3/reports)

Initiate a report export. The report is generated asynchronously.

Endpoint: POST /api/v3/reports

Request Body Structure:

{
  "type": "<REPORT_TYPE>",
  "subType": "<SUB_TYPE>",
  "format": "csv",
  "fileName": "<optional-custom-filename>",
  "reportMeta": {
    "columns": ["<column_key_1>", "<column_key_2>", ...],
    "filter": "<optional-JSON-filter-string>",
    "searchKey": "<optional-text-search>"
  }
}

Report Types

Export

Type

Sub Type

Findings

FINDINGS

FINDINGS_W_ASSETS

Unique Findings

FINDINGS

FINDINGS

Assets

SIGMA_ASSETS

ASSETS

Software

ASSET_SOFTWARES

(not required)

Example: Export Findings with specific columns and filter

curl -X POST 'https://<TENANT_URL>/api/v3/reports' \
  -H 'Authorization: Bearer <ACCESS_TOKEN>' \
  -H 'Content-Type: application/json' \
  -d '{
    "type": "FINDINGS",
    "subType": "FINDINGS_W_ASSETS",
    "format": "csv",
    "fileName": "findings-export",
    "reportMeta": {
      "columns": ["findingName", "severity", "cveIds", "epss", "assetName"],
      "filter": "{\"criterion\":{\"attribute\":\"severity\",\"operator\":\"IN\",\"value\":[\"Critical\",\"High\"]}}"
    }
  }'

Example: Export Unique Findings

curl -X POST 'https://<TENANT_URL>/api/v3/reports' \
  -H 'Authorization: Bearer <ACCESS_TOKEN>' \
  -H 'Content-Type: application/json' \
  -d '{
    "type": "FINDINGS",
    "subType": "FINDINGS",
    "format": "csv",
    "fileName": "unique-findings-export",
    "reportMeta": {
      "columns": ["findingName", "severity", "score", "cisaKev", "epss"]
    }
  }'

Example: Export Assets

curl -X POST 'https://<TENANT_URL>/api/v3/reports' \
  -H 'Authorization: Bearer <ACCESS_TOKEN>' \
  -H 'Content-Type: application/json' \
  -d '{
    "type": "SIGMA_ASSETS",
    "subType": "ASSETS",
    "format": "csv",
    "fileName": "assets-export",
    "reportMeta": {
      "columns": ["assetName", "assetTypes", "criticality", "zone", "cloudRegion"]
    }
  }'

Example: Export Software for an asset

curl -X POST 'https://<TENANT_URL>/api/v3/reports' \
  -H 'Authorization: Bearer <ACCESS_TOKEN>' \
  -H 'Content-Type: application/json' \
  -d '{
    "type": "ASSET_SOFTWARES",
    "format": "csv",
    "fileName": "software-export",
    "reportMeta": {
      "assetId": "<ASSET_ID>"
    }
  }'

Poll Report Status (GET /api/v3/reports)

Check the status of your reports.

curl -X GET 'https://<TENANT_URL>/api/v3/reports' \
  -H 'Authorization: Bearer <ACCESS_TOKEN>'

Response includes a list of reports with their current status (IN_PROGRESS, SUCCESS, or FAILED).

Download Report (GET /api/v3/reports/:uuid)

Once the report status is SUCCESS, download it using the report UUID:

curl -X GET 'https://<TENANT_URL>/api/v3/reports/<REPORT_UUID>' \
  -H 'Authorization: Bearer <ACCESS_TOKEN>'

This returns a pre-signed S3 URL valid for 5 minutes. Use this URL to download the CSV file:

curl -o report.csv '<PRE_SIGNED_URL>'

Filter Syntax

The filter field in reportMeta accepts a JSON string with the following structure:

Single criterion:

{
  "criterion": {
    "attribute": "<ATTRIBUTE_NAME>",
    "operator": "<OPERATOR>",
    "value": <VALUE>
  }
}

Multiple conditions:

{
  "logicalCondition": "AND",
  "conditions": [
    { "criterion": { "attribute": "severity", "operator": "IN", "value": ["Critical", "High"] } },
    { "criterion": { "attribute": "cisaKev", "operator": "EQUALS", "value": true } }
  ]
}

Supported operators:

Operator

Description

Value Type

EQUALS

Exact match

string / boolean

LIKE

Pattern match (SQL LIKE)

string

NOT LIKE

Negated pattern match

string

CONTAINS

Substring match

string

NOT CONTAINS

Negated substring match

string

IN

Value in list

array

NOT IN

Value not in list

array

BETWEEN

Range (inclusive)

array [min, max]

NOT BETWEEN

Outside range

array [min, max]

Note

All operator values must be UPPERCASE.

Reports History Page

All generated reports are accessible from the Reports page in the left navigation.

The Reports page shows:

  • Name — auto-generated report name with timestamp

  • Requested By — email of the user who initiated the export

  • Requested At — timestamp of when the export was initiated

  • Status — current status (In Progress / Success / Failed)

  • Download — download button (available when status is Success)

You can toggle between My Reports and All Reports (admin only) views.

Reports are retained for 7 days after generation, after which they expire and are no longer downloadable.

Export Limits

Export Type

Maximum Rows

Maximum File Size

Findings Report

2,500,000

5 GB

Unique Findings Report

2,500,000

5 GB

Asset Report

1,000,000

5 GB

Software Report

250,000

5 GB

Notes

  • These limits apply uniformly to both UI and API exports.

  • If the export exceeds the row limit, only the first N rows (sorted by exposure score descending) are included.

  • Reports are exported as CSV format.

  • A duplicate report check prevents regenerating the same report within 60 minutes.