Customize queries

Prev Next

Create custom queries using ePO - SaaS query system and reuse them in dashboard monitors and report sections.

We provide an overview on using ePO - SaaS query capabilities for gathering TIE information.

  • The TieServerSchema retrieves information about enterprise reputation, files, and certificates from the TIE.

  • The ePO schema queries about client and threat events enriched by TIE services information.

  1. In ePO - SaaS, select Queries & ReportsNew Query.

  2. In the drop-down list for Datasource Type, select a schema:

    • TieServerSchema — On the Result Type tab, select which results are displayed, then click Next.

      Option definitions

      Option

      Definition

      Files

      • File Enterprise Reputation — Retrieves summarized Enterprise reputation for files.

      • File Reputation — Retrieves summarized non-enterprise reputation for files from the TIE.

      • Files — Retrieves file information from the TIE.

      • New Files on Systems — Retrieves information about systems with new files.

      TIE Data Storage Management

      Cleanup Trending Summary — Retrieves TIE services cleanup trending summary.

      Certificates

      • Certificate Enterprise Reputation — Shows the enterprise reputation of the certificates.

      • Certificate Reputation — Retrieves summarized non-enterprise reputation for certificates from the TIE.

      • Certificates — Retrieves certificate information fromTIE.

      • New Certificates on Systems — Retrieves information about systems with new certificates.



    • ePO — Select Events and follow the prompts.

  3. On the Chart tab, customize how the results are displayed, then click Next.

  4. On the Columns tab, customize the columns for displaying the results, then click Next.

  5. On the Filter tab, narrow the results of your query using the drop-down list, then click Run.

You obtain a customized chart with the threat intelligence information from your TIE services.