You can use the Endpoint data by using the following instructions to add the Endpoint information into Reports. The Endpoint Integration Guide provides an overview of Endpoint integration into RSA NetWitness Platform.
Make sure that:
- You have configured the Endpoint alerts via syslog into a Log Decoder. For more information see, "Configure Endpoint Alerts Via Syslog into a Log Decoder" topic in Endpoint Integration Guide).
To integrate Endpoint information into Reports:
- In Reporting Engine> View> Config> Sources.
- Add the Concentrator that is consuming data from the Log Decoder as a data source.
Endpoint meta is populated in Reporting Engine.
- Run reports by selecting the appropriate meta.