using find / update in securitycenter reports a “how to” guide for securitycenter

14
Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Upload: reginald-hawkins

Post on 17-Jan-2018

223 views

Category:

Documents


0 download

DESCRIPTION

Address Repository Scan Policy Severity IAVM ID DNS Name Asset Audit File CVE ID Find / Update Filter The Find / Update tool can update the following filters:

TRANSCRIPT

Page 1: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Using Find / Update in SecurityCenter Reports

A “How To” Guide for SecurityCenter

Page 2: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Updating Filters in a Report

• SecurityCenter reporting is very powerful because of many filtering options available.

• In some cases, changing the filters can be difficult.

• Tenable provides a “Find/Update” button for several filters.

Page 3: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

• Address• Repository• Scan Policy• Severity• IAVM ID

• DNS Name• Asset• Audit File• CVE ID

Find / Update Filter

The Find / Update tool can update the following filters:

Page 4: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Where is this?

• The Find / Update link is located on the top of the “Definition” tab when editing a report.

Page 5: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Find / Update Filters

Page 6: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Search Filters

• This example will update the audit file field.• Click Add Filter, and click on Audit File

Page 7: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Is Set or Is Not Set, that is the question?

• This example uses a search for filters where the Audit File field is not used or is empty.

• In Search Filters, add a filter to look for the unused field.– “Audit File” “Is Not Set”

• In Update Action, add an action to add the audit filter to the filters.– “Audit File” “Is Set” “File Name”

Page 8: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Search Filters

• The Search Filter is going to look for the filter condition currently in use that needs to be updated.

• In this example, an update to the Audit File field is reviewed.

• If the audit file field is not currently in use, then select the “Is Not Set”.

• Please note that the “Save” button must be selected.• In this example, the audit file field is not set.

Page 9: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Matching Filter Found

• After clicking on the Save button, the matching filters in the report will be shown below.

Page 10: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Add Action

• The next step is to add an action.• Click “Add Action”• To add the audit file filter, choose “Is Set

To”, then select the appropriate audit file.• Click the Save button

Page 11: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Update Action Saved

• The update action is saved, yet is not applied.• Now review the settings that are going to

change.

Page 12: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Update

• To apply the updates, click the Update button.• Click Close to complete the update process.

Page 13: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

Verify the Filter Change• Navigate to any of the components in the

report, and verify the filter has changed.

Page 14: Using Find / Update in SecurityCenter Reports A “How To” Guide for SecurityCenter

For Questions Contact

Tenable Customer Support Portalor

Cody Dumont in the SecurityCenter Section of the Tenable Discussion Forums