Previous Topic: Custom Log CollectionNext Topic: Agent Management


Custom Report Creation

Custom Query Definition

Problem:

The security analyst needs a query for a report or action alert that is not available out-of-the-box.

Solution:

The security analyst, assigned an Analyst role, creates a query with the CA User Activity Reporting Module query builder, and saves and tags it for quick identification and usage in the future.

Procedure

More Information

Creating a Query

Using Tags

Create a Query to Retrieve Only Severe Events

 

Background info:

About Queries and Reports

Customizing Queries for Action Alerts

Custom Dashboard (multi-query)

Problem:

The security analyst needs to view the results of multiple queries, where such a report is not available out-of-the-box.

Solution:

The security analyst, assigned an Analyst role, creates a report based on two or more queries with the CA User Activity Reporting Module report builder and tags it for quick identification and future usage.

Procedure

More Information

Creating a Report

Using Tags

Example scenario of creating a report from three existing queries:

Creating a Custom Report