hello,
if you just want to do a report on 5 specific users, you just need to define a filter on sender/username/... apply it and then save it. After that you could even schedule it to run every night and send result to some people.
If you want to aggregate different type of DLP incident (network, discover, endpoint) for these users you have two solutions :
- create 3 different reports
- use DLP 12.5 as there is a new functionality named User Risk, who perform this aggregation between all type of incident.
Regards.