This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
OK
  • RSA.com
  • Products
    • Archer®
      • Archer®
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Archer® Exchange
      • Training
      • Upcoming Events
      • Videos
    • RSA® Fraud & Risk Intelligence Suite
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Web Threat Detection
      • Upcoming Events
      • Videos
    • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Cloud
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Patch Content
      • Videos
    • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication Mobile SDK
      • Advisories
      • Events
      • Ideas
      • Knowledge Base
      • Request Access
      • Training
    • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication for eCommerce
      • RSA® Adaptive Authentication for eCommerce
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® FraudAction Services
      • RSA® FraudAction Services
      • Advisories
      • Discussions
      • Documentation
      • Ideas
      • Videos
    • RSA® Web Threat Detection
      • RSA® Web Threat Detection
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Videos
    • RSA NetWitness® Platform
      • RSA NetWitness® Platform
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA NetWitness® Detect AI
      • RSA NetWitness® Detect AI
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Investigator
      • RSA NetWitness® Investigator
      • Documentation
      • Download the Client
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Orchestrator
      • RSA NetWitness® Orchestrator
      • Overview
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA SecurID® Suite
      • RSA SecurID® Suite
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Knowledge Base
      • Ideas
      • Integrations
      • Training
      • Videos
    • RSA® Identity Governance & Lifecycle
      • RSA® Identity Governance & Lifecycle
      • Advisories
      • Blog
      • Community Exchange
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA SecurID® Access
      • RSA SecurID® Access
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • Other RSA® Products
      • Other RSA® Products
      • RSA® Access Manager
      • RSA® Data Loss Prevention
      • RSA® Digital Certificate Solutions
      • RSA enVision®
      • RSA® Federated Identity Manager
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
  • Resources
    • Advisories
      • Product Advisories on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Hosted
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Product Advisories
    • Blogs
      • Blogs on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Blogs on RSA Link
    • Discussion Forums
      • Discussion Forums
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Discussion Forums on RSA Link
    • Documentation
      • Product Documentation
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Downloads
      • Product Downloads
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Downloads on RSA Link
    • Ideas
      • Idea Exchange
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Knowledge Base
      • Knowledge Base
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Knowledge Base Pages on RSA Link
    • Upcoming Events on RSA Link
      • Upcoming Events
    • Videos
      • Videos on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Videos on RSA Link
  • Support
    • RSA Link Support
      • RSA Link Support
      • News & Announcements
      • Getting Started
      • Support Forum
      • Support Knowledge Base
      • Ideas & Suggestions
    • RSA Product Support
      • RSA Product Support
      • General Security Advisories and Statements
      • Product Life Cycle
      • Support Information
      •  
      •  
      •  
      •  
      •  
  • RSA Ready
  • RSA University
    • Certification Program
      • Certification Program
    • Course Catalogs
      • Course Catalogs
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • On-Demand Subscriptions
      • On-Demand Subscriptions
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • Product Training
      • Product Training
      • Archer®
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Identity Governance & Lifecycle
      • RSA NeWitness® Platform
      • RSA SecurID® Access
    • Student Resources
      • Student Resources
      • Access On-Demand Learning
      • Access Virtual Labs
      • Contact RSA University
      • Enrollments & Transcripts
      • Frequently Asked Questions
      • Getting Started
      • Learning Modalities
      • Payments & Cancellations
      • Private Training
      • Training Center Locations
      • Training Credits
      • YouTube Channel
    • Upcoming Events
      • Upcoming Events
      • Full Calendar
      • Conferences
      • Live Classroom Training
      • Live Virtual Classroom Training
      • Webinars
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

Visit the Known Issues dashboard if you are experiencing issues on RSA Link

View Dashboard

RSA enVision® Discussions

Browse the RSA enVision discussion board to get product help and collaborate with other users of RSA enVision.
  • RSA Link
  • :
  • Products
  • :
  • Other RSA Products
  • :
  • RSA enVision
  • :
  • Discussions
  • :
  • RSA Envision custom report using aggregates in SQL...
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page
BalajiSastry
BalajiSastry Beginner
Beginner
‎2013-09-17 09:31 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

RSA Envision custom report using aggregates in SQL clause gives error

I would like to create a Windows failed logons report that shows users exceeding 50 failed logons. How can I specify criteria to show me failed logons that exceed a number say 50. When I put in criteria where count(username) > 50, I get an error

Invalid SQL WHERE clause: .
ASA Error -150: Invalid use of an aggregate function.

Thanks for your help.

  • Tags:
  • Community Thread
  • Discussion
  • enVision
  • Forum Thread
  • Reports
  • rsa
  • RSA enVision
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
9 Replies
RSAAdmin
RSAAdmin Beginner
Beginner
‎2013-09-17 06:15 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Please consider moving this question as-is (no need to recreate) to the proper forum for maximum visibility.  Questions written to the users' own "Discussions" space don't get the same amount of attention and can go unanswered for a long time.

 

You can do so by selecting "Move" under ACTIONS along the upper-right.  Then search for and select: "RSA enVisilon".

 

For further guidance on engaging with the communities please refer to the [DEAD LINK /docs/DOC-24433]IIG Communities Getting Started Guide.

0 Likes
Share
Reply
BalajiSastry
BalajiSastry Beginner
Beginner
In response to RSAAdmin
‎2013-09-17 07:03 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Thanks, I have moved the discussion.

0 Likes
Share
Reply
UMBERTOZANATTA1
UMBERTOZANATTA1 Beginner
Beginner
In response to BalajiSastry
‎2013-10-08 09:45 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi,

 

you can't do that. In my opinion the easiest way is use a correlation rule and an alarm.

0 Likes
Share
Reply
DelfinAbzueta
DelfinAbzueta Beginner
Beginner
‎2013-10-14 08:29 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi BalajiSastry

 

Consider to include a field like count(MessageID) as select fields when you are creating the report, then you can use it to validate the numbers of ocurrences in the where clause.

 

creando_reportes.JPG.jpg

 

Cheers,

0 Likes
Share
Reply
PavelYosifov
PavelYosifov Beginner
Beginner
‎2013-10-16 08:39 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi BalajiSastry,

 

I would say that uzanatta is right. You can use a correlation rule and then create an alarm. You can then create a report based on that alarm.

Reports in enVision are ... limited in functionality. Everything you do when you configure a report is to filter only.

So actually you cannot relate events in reports. The system will never count how many times this has happened for this particular user, etc. That is a drawback of IPDB, actually.

DelfinAbzueta's suggestion will give you them total number of failed login events, but will not relate them to the same user...

So you will only see a number there - 2146 - and it will be for all users.

One report, that might just do it for you is TOP 10 failed logins by account. I think you can find it pre-built in enVision, or if not let me know and I can share the report with you. It's a graph chart, that will show you for a certain period the amount of failed logins that users have generated and show them for a specific user.

For example it will show you sysadmin - 56, tsmuser - 34, admin -12, etc.

The problem is that you cannot put a threshold of 50 here, so it could only show you the ones with more than 50...

0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to PavelYosifov
‎2013-11-22 03:37 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

I want to get Top 10 failed login by account using backup end sql query. For that how to to sql connectivity using command prompt ?

 

This is required to combine two or more dashboard view using backend utility. However i tried using lsdata but no result.

 

Regards

Anant

0 Likes
Share
Reply
RafaelAggeler
RafaelAggeler Beginner
Beginner
‎2013-12-09 02:57 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

There is actually a way of doing this, but you will not be able to modify the report through the  Web-GUI anymore, as the Web-Gui doesn't support it. But you can still run the report from Web-GUI of course!

So if you're interested in that anyway,...let me know 😉

0 Likes
Share
Reply
KevinBanyai
KevinBanyai Beginner
Beginner
In response to RafaelAggeler
‎2013-12-26 06:49 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

I am interested... let's hear it

0 Likes
Share
Reply
RafaelAggeler
RafaelAggeler Beginner
Beginner
In response to KevinBanyai
‎2014-01-20 03:36 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi there

 

sorry for the late answer, Christmas and so on,...:-)

Well, I'll try to explain with an own report at first:

We create a report on the Windows table and select SourceAddress, Username, count(UserName) as fields.

Next we filter for MessageID Security_675, Username shall be longer than 4 characters and shall not end on '$'. We sort by count(Username) descending, the order of the fields is: SourceAddress, UserName, count(UserName).

 

The resulting XML looks like this:

<?xml version="1.0" encoding="UTF-8"?>

<report name="SomeReportName" dateTimeStamp="false" runtimeChecked="false" resultLimit="-1" distinct="false" regex="false" resolve="false"><description/><table name="Windows"/><chart><fieldList><field name="SourceAddress" sort="none" title="SourceAddress"/><field name="UserName" sort="none" title="UserName"/><field name="count(UserName)" sort="descending" title="count(UserName)"/></fieldList></chart><variables/><sql><![CDATA[MessageID = 'Security_675_Security' AND char_length(UserName) > 4 AND UserName NOT LIKE '%$' ]]></sql></report>

 

The interesting part is BOLD. As we know there's a Sybase DB in the back-end, so we might use all commands a Sybase database accepts. Unfortunately the enVision Web-UI does not accept them (partly because we have no control over ordering the statements, so they end up in a wrong order for Sybase and it would not work anyway...).

 

Let's change the bold statement above to the following:

MessageID = 'Security_675_Security' AND char_length(UserName) > 4 AND UserName NOT LIKE '%$') GROUP BY "saddr","username" HAVING COUNT(UserName) > 30 ORDER BY 3 DESC /*

 

Ok. What does it do? First part till NOT LIKE '%$' is same as before. Now we got a closing bracket there. Why? Because RSA enVision creates an opening bracket before the whole filter construct, but we just don't ever see that one. So we need to close it to be able to continue with our own statement.

Next comes the GROUP BY statement, which groups the results by sourceaddress and username. Then we got a HAVING COUNT(UserName) > 30 which will only show results that have a count higher than 30 and finally the ORDER BY 3 DESC /*.

ORDER BY 3 DESC orders the result by the count (it's in third position of the fields we selected, therefore 3).

And really important: /* comments out the whole rest of the SQL statement that RSA enVision would append to the report query. As we just created our own query here we don't need the rest that RSA enVision would append, so we comment it out. Actually we have to comment it out as the query will not be accepted by Sybase anymore,...it would be a really ugly mix between our own query and RSA enVision statements 😉

 

As mentioned before: You need to do those changes in the report XML directly, and afterwards you need to restart the NIC Webserver Service. You can't modify that report in the WEB-UI anymore.

 

Hope that's clear more or less,...otherwise just ask.

 

Regards

Rafael

0 Likes
Share
Reply
Powered by Khoros
  • Products
  • Resources
  • Solutions
  • RSA University
  • Support
  • RSA Labs
  • RSA Ready
  • About RSA Link
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
© 2020 RSA Security LLC or its affiliates.
All rights reserved.