‎2009-09-03
06:33 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Compliance Reports using two tables
I have created an alert that monitors what SSHs into our Linux machines and then where they su to. I have a watch list that I created to monitor certain ids and this is working perfectly. When I try to create a report so I can see everything that has connected and had successful su...it uses different tables. I am not able to get past this point. There are two seperate reports that are canned that show this but I need one that has both together so I can see the progression on what the user is doing. Any suggestions?
5 Replies
‎2009-09-03
06:55 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Did you try looking at Global Table that contains some common set of variables? You may have to check if your table variables are available in global table or not accordingly you can generate a report using global table.
‎2009-09-03
07:08 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
This does not have a foreign address field...I would need something that still shows the foreign address to see where and/or who it doing the connections or su.
‎2009-09-03
07:12 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
as far as I know Global table has faddr/daddr field (foreign/destination), are you not seeing them?
‎2009-09-03
07:15 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
no I do not see the faddr but I do see the daddr
‎2009-09-03
07:18 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I was mistaken I just see the device address that the action was taken place on.
