Symantec Security Expressions Server manual Policies, Add Task, Update Task, Cancel

Page 31

Configure Servers

target for every week, month, year, or overall.

If you select Yearly, for example, the database will retain the last audit performed on every policy file and on every target audited for every year you've audited using this database. Because cleanups occur nightly, the last audit saved during the current year could potentially change nightly until the year ends. If you select Overall, however, only the most recent audit performed on each policy file and on each target remains in the database after each nightly cleanup.

The application recognizes the span of a week to be when weeks are configured to start and end in the database.

Discard audits older than __ days that failed to run or had errors only - Cleanup occurs only to data from audits that failed to run or audits where all rules had Error ratings. Type the number of days for which you want to retain data before deleting it.

Audit Types

If you want to clean up audit data generated from certain audit types only, check the boxes next to the audit types.

Audit-on-Connect and self service - Cleans up data from only Audit-on-Connect audits and self-service audits.

Scheduled - Cleans up data from only scheduled audits, including audits scheduled in any console application connected to the same database the server application uses. It also includes audits performed through the Web service.

Console interactive - Cleans up data from only audits performed in the console application's Audit tab.

COM object and command line - Cleans up data from only audits performed through the COM object and the command line. Audit results imported through the command line are considered command-line audits regardless of what kind of audit produced the results.

Policies

All policy files (.sif) used to generate audit data in the database are listed. If you want to clean up audit data generated from certain policy files only, check the boxes next to the policy files.

If you leave all boxes unchecked, scheduled cleanups include all policy files listed plus any new policy files used in audits performed after configuring this cleanup task. If you check all boxes, scheduled cleanups include just those policy files.

Add Task

If you're creating a cleanup task, this button appears. Click it to save the options you set as a new cleanup task.

Update Task

If you're modifying an existing cleanup task, this button appears. Click it to update the task with the new settings.

Cancel

Click this button to cancel creating a new cleanup task or modifying an existing cleanup task.

23

Image 31
Contents SecurityExpressions Server User Guide Page Table Of Contents Page Table Of Contents Page Vii Page Contacting Us Page Contacting Technical Support Technical SupportPage SecurityExpressions Console Other ProductsPage About SecurityExpressions Audit & Compliance Server OverviewPage How to Audit your Local Computer Self-Service AuditWhat is Self-Service Auditing? Self-Service Audit AgreementDisplays on the page. No detailed audit results appear Pages with Role Settings Configure ServersAbout Server Configuration Local Server SettingsViewing Audit Results SetupDatabase Connection Windows 2000 Servers Secure ConnectionCredential Store User Click OK on the Default Web Site Properties windowCreating Credential Stores Site Preferences Enable Web ServicesSecurityExpressions Console Credential Stores Software RegistrationAccess Item Rights Global Machine List Access User RolesLibrary Synchronization Policy File LibraryCheck the Synchronize with a policy file library box How System Scores are Calculated About Policy FilesDefault method for remote execution on Windows Agent & Service ConfigurationTarget Options SSH Agent Authentication Database Cleanup Add Task Update TaskCancel PoliciesSite Preferences Agent DownloadsClick Use the Following Agreement Allow Remediation Page Policies Table What is Audit-on-Connect?Audit-On-Connect PoliciesPage Adding Policies Editing Policies Deleting Policies Configuring with Run-Time Policy VariablesPage Scopes ScopesAdd a New Scope Page Edit a Scope Scopes Table Supported Operators Deleting ScopesDNS Domain Name Scopes Expression ScopesOrg Unit Scopes Supported FunctionsDetection Method Scopes Notifications Editing Notifications Creating New Command NotificationsCreating New Email Notifications Click Add NewClick Add New Creating New Command Notifications Notification Variables Deleting NotificationsAdding Exceptions ExceptionsExceptions Exceptions Table Column DescriptionConnection Monitors Specify Password and Encrypted PasswordConnection Monitors Deleting ExceptionsRemove Configuring Connection MonitorsEnabling Connection Monitors IP Range Section Connection Monitor Configuration FileOptions DefaultConfiguration File Syntax Processing the Configuration FileActive Directory Active Directory Connection Monitor only Slow Links NetworkInitial Token Trace Route InformationNetwork Admissions Control Unmanaged SystemsRedirection Web HealthyQuarantined/Unknown Reaudit if quarantinedRedirection Web Page Behavior Audit on Connect TracingAudit on Connect Tracing Page Page Audit-On-Schedule What is Audit-on-Schedule?Page Adding Policies Editing Policies Deleting Policies Page Notifications Click Add New Click Add New Deleting Notifications My Machine Lists My Machine ListsEditing Machine Lists Adding Machine ListsScheduled Tasks Scheduled TasksDeleting Machine Lists Editing Global Machine ListsAdding Scheduled Tasks Basic SettingsSchedule Settings Hosts Not Connected Settings Credentials Settings Other Options SettingsEditing Scheduled Tasks Windows Group AccessSchedule Settings Notifications Other Options Settings Deleting Scheduled Tasks Page Adding a New Audit-On-Connect Report Profile View Audit-On-Connect ActivityBrowse Audit-On-Connect Activity Audit-On-Connect Activity Table Column DescriptionDeleting Report Profiles Editing Report ProfilesAudit-On-Connect Exceptions Report Audit-On-Connect Error Log ReportPage Browse Audit Results View Audit ResultsAdding a New Audit Results Report Profile Page Deleting Audit Report Results Profiles Scheduled Audits Log ReportAdding Custom Reports to the Server Application Editing Audit Report Results ProfilesPage Glossary Page Index ConfigureIP address 33, 44, 45 Rule weights