Symantec Security Expressions Server manual Schedule Settings

Page 76

SecurityExpressions Server User Guide

Policies page.

Only the policies to which you have Use access rights appear for selection. Access rights for individual policies are set in the Windows Group Access options on the

Policies page. If you can't find a policy you need to use, ask the policy's creator to add you to one of the Windows User Groups with Use access rights to the policy.

5.Select which machine list(s) you want to audit every time this task runs.

You may select any combination of machine lists from the Global Machine Lists, My Machine Lists, and Other User's Shared Machine Lists sections.

Only the machine lists to which you have Use access rights appear for selection. Access rights are set in the Windows Group Access options on the My Machine Lists page and

the ML Access page (global machine lists). If you can't find a machine you need to use, ask the machine list's creator or administrator to add you to one of the Windows User Groups with Use access rights to the machine list.

The Global Machine Lists section displays all machine lists in the SecurityExpressions Console, if your organization uses the console.

If the SecurityExpressions Console's database does not contain any machine lists, this section won't contain any machine lists.

If you created any machine lists on the My Machine Lists page using the same user account as the one you're using to create this task, the My Machine Lists

section displays those machine lists.

If the My Machine Lists page does not contain any machine lists created using the same user account as the one you're using to create this task, this section won't

contain any machine lists.

If anyone created any machine lists on the My Machine Lists page using a different user account than the one you're using to create this task, and entered a Windows User Group in the Use Machine List field that you're a member of, the

Other User's Shared Machine Lists section displays those machine lists.

If the My Machine Lists page does not contain any machine lists that 1) were created using a different user account than the one you're using to create this task and 2) contain a Windows User Group in the Use Machine List field that you're a member of, this section won't contain any machine lists.

6.In the Server to Run On drop-down list, select which server you want run the task.

You can install the server software on more than one server system, as long as they all connect to one central database. Each server can have its own settings. Based on the way each server is configured, you'll want to use one particular server to perform the audits executed by this task, depending on your goals.

Schedule Settings

7.Select to run this task once, weekly, monthly, or not at all.

Not Scheduled - Lets you create a scheduled task without enabling it, or disable an existing scheduled task without deleting it.

68

Image 76
Contents SecurityExpressions Server User Guide Page Table Of Contents Page Table Of Contents Page Vii Page Contacting Us Page Technical Support Contacting Technical SupportPage Other Products SecurityExpressions ConsolePage Overview About SecurityExpressions Audit & Compliance ServerPage Self-Service Audit What is Self-Service Auditing?Self-Service Audit Agreement How to Audit your Local ComputerDisplays on the page. No detailed audit results appear Configure Servers About Server ConfigurationLocal Server Settings Pages with Role SettingsViewing Audit Results SetupDatabase Connection Secure Connection Windows 2000 ServersCredential Store User Click OK on the Default Web Site Properties windowCreating Credential Stores Enable Web Services SecurityExpressions Console Credential StoresSoftware Registration Site PreferencesAccess Global Machine List Access User Roles Item RightsLibrary Synchronization Policy File LibraryCheck the Synchronize with a policy file library box About Policy Files How System Scores are CalculatedDefault method for remote execution on Windows Agent & Service ConfigurationTarget Options SSH Agent Authentication Database Cleanup Update Task CancelPolicies Add TaskSite Preferences Agent DownloadsClick Use the Following Agreement Allow Remediation Page What is Audit-on-Connect? Audit-On-ConnectPolicies Policies TablePage Adding Policies Editing Policies Configuring with Run-Time Policy Variables Deleting PoliciesPage Scopes ScopesAdd a New Scope Page Edit a Scope Scopes Table Deleting Scopes DNS Domain Name ScopesExpression Scopes Supported OperatorsOrg Unit Scopes Supported FunctionsDetection Method Scopes Notifications Creating New Command Notifications Creating New Email NotificationsClick Add New Editing NotificationsClick Add New Creating New Command Notifications Deleting Notifications Notification VariablesExceptions ExceptionsExceptions Table Column Description Adding ExceptionsSpecify Password and Encrypted Password Connection MonitorsDeleting Exceptions Connection MonitorsRemove Configuring Connection MonitorsEnabling Connection Monitors Connection Monitor Configuration File IP Range SectionDefault OptionsConfiguration File Syntax Processing the Configuration FileActive Directory Active Directory Connection Monitor only Network Slow LinksTrace Route Information Network Admissions ControlUnmanaged Systems Initial TokenHealthy Quarantined/UnknownReaudit if quarantined Redirection WebRedirection Web Page Behavior Audit on Connect TracingAudit on Connect Tracing Page Page What is Audit-on-Schedule? Audit-On-SchedulePage Adding Policies Editing Policies Deleting Policies Page Notifications Click Add New Click Add New Deleting Notifications My Machine Lists My Machine ListsAdding Machine Lists Editing Machine ListsScheduled Tasks Deleting Machine ListsEditing Global Machine Lists Scheduled TasksBasic Settings Adding Scheduled TasksSchedule Settings Hosts Not Connected Settings Other Options Settings Credentials SettingsWindows Group Access Editing Scheduled TasksSchedule Settings Notifications Other Options Settings Deleting Scheduled Tasks Page View Audit-On-Connect Activity Browse Audit-On-Connect ActivityAudit-On-Connect Activity Table Column Description Adding a New Audit-On-Connect Report ProfileEditing Report Profiles Deleting Report ProfilesAudit-On-Connect Error Log Report Audit-On-Connect Exceptions ReportPage Browse Audit Results View Audit ResultsAdding a New Audit Results Report Profile Page Scheduled Audits Log Report Adding Custom Reports to the Server ApplicationEditing Audit Report Results Profiles Deleting Audit Report Results ProfilesPage Glossary Page Configure IndexIP address 33, 44, 45 Rule weights