Symantec Security Expressions Server Server User Manual


 
SecurityExpressions Server User Guide
78
2. Select one or more Detection Methods. The detection method identifies the
Connection Monitor types.
3. Define filters that cause only certain events that meet your criteria to display in the
report. Click the links and set the criteria. You may set as many kinds of filters as you
like. The report's contents are based on a combination of all filters you set.
Note: When you click a new link, the options from the previous link no longer display but
any options you selected there are still selected. To help you remember which links have
filters selected, a check mark appears next to them.
Group Posture Results - Select as many as you want.
Device Type - Select as many as you want.
Enter MACs - Type the MAC addresses you want to use as criteria. One per line.
Enter IP Addresses - Type the IP addresses you want to use as criteria. One per line.
Enter Device Name - Type the device names you want to use as criteria. One per line.
Scope Name – Select as many as you want. More than one Policy can apply to a Scope. If
you do not filter by policy, all data displays.
If a computer is listed in multiple scopes, the only Windows Group Access settings that
apply to the audit results are the ones from the scope used by the audit.
4. In the Show Fields section, check the boxes to choose which additional columns you
want to appear in the summary report of this profile.
5. Under Date/Hour Range Selection, select one of the following options and set a
range of data to display each time the report runs.
Open or closed range beginning on a specific day - Includes in the report a range
of connection activity starting on a specific date. You may specify an end for the
date range or let the report display all activity available after the starting date.
Relative range from the current date - Includes in the report a range of connection
activity prior to the day the report ran. Enter how many days, hours and minutes
worth of prior data you want to display in the report.
6. Select Most Recent Audit to show the most recent audit only and remove duplicate
data.
7. Click Save to save this report profile.
Editing Report Profiles
To edit a report profile, click the Edit hyperlink and modify the same settings as during the profile
creation.
Deleting Report Profiles
To delete a report profile:
1. Click the Edit hyperlink on the Browse Audit-On-Connect Activity table to select the
report profile to remove.