Custom Query Definition
The security analyst needs a query for a report or action alert that is not available out-of-the-box.
The security analyst, assigned an Analyst role, creates a query with the CA Enterprise Log Manager query builder, and saves and tags it for quick identification and usage in the future.
Procedure |
More Information |
---|---|
Create a Query to Retrieve Only Severe Events
|
Background info: |
Custom Dashboard (multi-query)
The security analyst needs to view the results of multiple queries, where such a report is not available out-of-the-box.
The security analyst, assigned an Analyst role, creates a report based on two or more queries with the CA Enterprise Log Manager report builder and tags it for quick identification and future usage.
Procedure |
More Information |
---|---|
Example scenario of creating a report from three existing queries: |
Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |