Symantec Security Expressions Server manual

Page 90

SecurityExpressions Server User Guide

Data Grid - Generates a highly interactive HTML report with lots of opportunities to drill down. Click the links and set the criteria. You may set as many kinds of filters as you like. The report's contents are based on a combination of all filters you set.

To learn more about the available filters, click here [click link again to close]

Note: When you click a new link, the options from the previous link no longer display but any options you selected there are still selected. To help you remember which links have filters selected, a check mark appears next to them.

Show Current Value - Check to add this column to the report. Show Description - Check to add this column to the report.

Policy - Select as many as you want.

Only the policies to which you have Use access rights appear for selection. Access rights are set in the Windows Group Access options on the Policies page. If you can't find a policy you need

to use, ask the policy's creator to add you to one of the Windows User Groups with Use access rights to the policy.

Scanned By - Select as many as you want. Scanned From - Select as many as you want.

Computers in Machine List - Displays the names of all machine lists, including both database machine lists created in the console and My Machine Lists created in this application. Select as many as you want.

Only the machine lists to which you have Use access rights appear for selection. Access rights are set in the Windows Group Access options on the My Machine Lists page and the ML Access page. If you can't find a machine list you need to use, ask the machine list's creator or administrator to add you to one of the Windows User Groups with Use access rights to the machine list. .

Crystal Report - Generates a Crystal report with the standard features. Select the report format from the scroll box.

PDF - Generates a PDF version of a Crystal report for easy transporting. Select the report format from the scroll box.

4.Select whether you want the report to include Audit-on-Schedule and Audit-on-Connect results or just Audit-on-Schedule results. In the Scheduled Audit Only list, select Yes for Audit- on-Schedule results only or No for both kinds of results.

5.In the Benchmark Score Less Than box, type the maximum score an audit must have in order for its results to display in the report. The results of any audit with a higher score than this will be considered not critical enough to appear in the report.

6.In the Show Fields section, check the boxes to choose which additional columns you want to appear in the summary report of this profile.

7.Under Date/Hour Range Selection, select one of the following options and set a range of data to display each time the report runs.

82

Image 90
Contents SecurityExpressions Server User Guide Page Table Of Contents Page Table Of Contents Page Vii Page Contacting Us Page Technical Support Contacting Technical SupportPage Other Products SecurityExpressions ConsolePage Overview About SecurityExpressions Audit & Compliance ServerPage Self-Service Audit Agreement Self-Service AuditWhat is Self-Service Auditing? How to Audit your Local ComputerDisplays on the page. No detailed audit results appear Local Server Settings Configure ServersAbout Server Configuration Pages with Role SettingsSetup Viewing Audit ResultsDatabase Connection Secure Connection Windows 2000 ServersClick OK on the Default Web Site Properties window Credential Store UserCreating Credential Stores Software Registration Enable Web ServicesSecurityExpressions Console Credential Stores Site PreferencesAccess Global Machine List Access User Roles Item RightsPolicy File Library Library SynchronizationCheck the Synchronize with a policy file library box About Policy Files How System Scores are CalculatedAgent & Service Configuration Default method for remote execution on WindowsTarget Options SSH Agent Authentication Database Cleanup Policies Update TaskCancel Add TaskAgent Downloads Site PreferencesClick Use the Following Agreement Allow Remediation Page Policies What is Audit-on-Connect?Audit-On-Connect Policies TablePage Adding Policies Editing Policies Configuring with Run-Time Policy Variables Deleting PoliciesPage Scopes ScopesAdd a New Scope Page Edit a Scope Scopes Table Expression Scopes Deleting ScopesDNS Domain Name Scopes Supported OperatorsSupported Functions Org Unit ScopesDetection Method Scopes Notifications Click Add New Creating New Command NotificationsCreating New Email Notifications Editing NotificationsClick Add New Creating New Command Notifications Deleting Notifications Notification VariablesExceptions Table Column Description ExceptionsExceptions Adding ExceptionsDeleting Exceptions Specify Password and Encrypted PasswordConnection Monitors Connection MonitorsConfiguring Connection Monitors RemoveEnabling Connection Monitors Connection Monitor Configuration File IP Range SectionDefault OptionsProcessing the Configuration File Configuration File SyntaxActive Directory Active Directory Connection Monitor only Network Slow LinksUnmanaged Systems Trace Route InformationNetwork Admissions Control Initial TokenReaudit if quarantined HealthyQuarantined/Unknown Redirection WebAudit on Connect Tracing Redirection Web Page BehaviorAudit on Connect Tracing Page Page What is Audit-on-Schedule? Audit-On-SchedulePage Adding Policies Editing Policies Deleting Policies Page Notifications Click Add New Click Add New Deleting Notifications My Machine Lists My Machine ListsAdding Machine Lists Editing Machine ListsEditing Global Machine Lists Scheduled TasksDeleting Machine Lists Scheduled TasksBasic Settings Adding Scheduled TasksSchedule Settings Hosts Not Connected Settings Other Options Settings Credentials SettingsWindows Group Access Editing Scheduled TasksSchedule Settings Notifications Other Options Settings Deleting Scheduled Tasks Page Audit-On-Connect Activity Table Column Description View Audit-On-Connect ActivityBrowse Audit-On-Connect Activity Adding a New Audit-On-Connect Report ProfileEditing Report Profiles Deleting Report ProfilesAudit-On-Connect Error Log Report Audit-On-Connect Exceptions ReportPage View Audit Results Browse Audit ResultsAdding a New Audit Results Report Profile Page Editing Audit Report Results Profiles Scheduled Audits Log ReportAdding Custom Reports to the Server Application Deleting Audit Report Results ProfilesPage Glossary Page Configure IndexIP address 33, 44, 45 Rule weights