Charts Were the Easy Part
I spent more than two years building Report Builder for Cisco Secure Network Analytics. I thought the hard part would be the charts. It wasn’t.
Our frontend team had three engineers. Across four GA releases, we shipped 17 report types and seven default dashboards.
The obvious work was tables and charts. The actual product stretched into permissions, parameters, schedules, exports, saved configurations, new telemetry, and a migration to Cisco’s Magnetic design system.
The chart was the part you could put in a screenshot. The hard part was making the same report stay correct for the right person, in every format, across multiple releases.
1. Users wanted answers, not charts
A security analyst opens a report to answer a question. Are the collectors receiving traffic? Were there any interruptions? Which hosts or alarms deserve a closer look?
To get there, someone has to choose a report, set a time range, select the right scope, and have access to the underlying data. Then the answer has to keep its meaning inside a dashboard, a scheduled email, a CSV, or a PDF.
A backend contract could tell us which values were valid. It could not decide which fields should be required, what the product should remember, or how someone should move from an overview to the evidence. Those looked like frontend decisions. They were product decisions.
2. Permissions changed the data
At first, permissions sound like a gate around the page. You can open Report Builder or you cannot. The real product was more complicated.
Someone could be allowed to use Report Builder without being allowed to see every host or every piece of network data. A chart could be correct against the full dataset and still be wrong for the person looking at it.
So permissions could not be an error we handled at the end. The parameters, request, chart, schedule, and export all had to agree about what that person was allowed to see. Authorization was part of the report itself.
3. Seventeen reports needed one product
Seventeen report types can turn into seventeen slightly different products surprisingly quickly. One asks for a host group. Another asks for a collector. A third needs a different time range or export format.
But people should not have to relearn Report Builder every time they choose a new report. Parameters, tables, charts, dashboards, and exports needed to feel like parts of the same system even when the underlying data changed.
Security software is dense for a reason. Removing hosts, protocols, traffic volumes, time ranges, or anomalies would make the product less useful. I stopped thinking simple meant fewer controls. Simple meant making the complexity predictable.
4. The feature was bigger than our team
Report Builder touched permissions, scheduling, exports, data, and the design system. A small change in the interface could require decisions from several teams.
We were also moving the product to Cisco’s Magnetic design system while new releases were already in flight. Clean components helped. They did not decide who owned a cross-team behavior or how every report should adopt it.
We needed written decisions and clear owners. The code could be perfectly organized and the product could still feel inconsistent.
5. Shipping exposed the real product
The first GA release felt like the finish line. Then customers showed up with saved configurations, unusual permission combinations, large result sets, and workflows we had never seen in a demo.
Then we added Zeek reporting. It brought many new log types, plus separate reports for collection trends, database ingest, and the logs themselves. At first, this looked like another set of tables. But every report still had to work with parameters, permissions, schedules, charts, and exports.
Shipping did not finish the feature. It revealed the parts of the product we could not see before customers used it.
Public product references
- Secure Network Analytics product overview
Cisco’s public overview of Secure Network Analytics.
- Secure Network Analytics 7.4.1 release notes
Cisco’s public record of Report Builder moving into the core product and expanding its telemetry reports.
- Secure Network Analytics 7.5.1 release notes
Cisco’s public record of report scheduling, customizable dashboards, PDF context, and reporting fixes.
- Secure Network Analytics Zeek Configuration Guide
Cisco’s public guide to Zeek telemetry in the product.
From reports to products
After more than two years, I stopped thinking of frontend engineering as the layer that renders the backend. It is where permissions, data, state, and user intent have to become one coherent product.
Cisco gave me ownership of a large part of that product. For my next step, I wanted to own the whole loop: the product, the customer, and the business. That is why I started Leversy.