Professional Documents
Culture Documents
2 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Reports
Reports are captured views or summaries of data that can be printed or
viewed in the ArcSight Console or ArcSight Command Center viewer in a
variety of formats.
© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Reports
• Use content available “out of the box”
! • PoC environment requires minimum level of effort
• Can be viewed with:
• ESM Console or Arcsight Command Center
• 3rd party utilities: PDF, Excel, RTF and CSV
• Report overall workflow:
1. Gather Report data (Active Lists, Session Lists, Notifications, Cases, Assets, Events, Trends)
2. Develop Report in Reports templates
3. Run as Scheduled Report or On Demand
• Data can be collected by :
• Running Queries on the ESM Database
• Using Trends
4 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
• Basic report templates are provided as standard
• For testing and basic reporting they are effective !
• Custom report templates can be created
• Very flexible
• Meet most report design requirements
• Requires extended knowledge of template editor
5 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
THE FOLLOWING EXAMPLE WILL ILLUSTRATE HOW TO BUILD A REPORT SHOWING TOP 10 FIREWALL EVENTS
6 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
7 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
8 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
9 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports –Templates
• Select to “Copy”
10 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
11 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
12 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
13 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
14 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
15 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
16 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
17 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
18 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Templates
19 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
• STOP!
• Before building reports
!
• Know what you want to report on!
• It may sound obvious but think about the data you are
going to report on
• How much will there be
• 1000 page reports do not look sexy
• Consider Fields you will use
• What (if any) aggregation will you use
20 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
21 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
22 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
• Queries are based on SQL logic:
• Select
• Group by
• Order by
• Functions available for grouping and sorting:
• Count
• Max
• Min
• Average
• Sum
• Time (grouping by time frame)
23 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
24 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
25 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
26 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
27 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
28 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
29 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
30 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports - Queries
31 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
• We now have:
• a template customized
• a Query
• Now we need to associate our template and our Query
• This will actually create the report
• In the Navigator Panel under Reports
• Select “Reports”
32 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
33 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
34 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
35 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
36 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
37 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
38 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
39 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
40 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
41 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
42 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
43 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
• Try to keep the time window short so you are not kept waiting for the result
44 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Creating Reports
45 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Lab: Create a report showing Top 10 IDS Events
46 © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Thank You
Questions ?
© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use