Create custom queries using ePO - SaaS query system and reuse them in dashboard monitors and report sections.
We provide an overview on using ePO - SaaS query capabilities for gathering TIE information.
The TieServerSchema retrieves information about enterprise reputation, files, and certificates from the TIE.
The ePO schema queries about client and threat events enriched by TIE services information.
In ePO - SaaS, select → .
In the drop-down list for Datasource Type, select a schema:
TieServerSchema — On the Result Type tab, select which results are displayed, then click Next.
Option definitionsOption
Definition
Files
File Enterprise Reputation — Retrieves summarized Enterprise reputation for files.
File Reputation — Retrieves summarized non-enterprise reputation for files from the TIE.
Files — Retrieves file information from the TIE.
New Files on Systems — Retrieves information about systems with new files.
TIE Data Storage Management
Cleanup Trending Summary — Retrieves TIE services cleanup trending summary.
Certificates
Certificate Enterprise Reputation — Shows the enterprise reputation of the certificates.
Certificate Reputation — Retrieves summarized non-enterprise reputation for certificates from the TIE.
Certificates — Retrieves certificate information fromTIE.
New Certificates on Systems — Retrieves information about systems with new certificates.
ePO — Select Events and follow the prompts.
On the Chart tab, customize how the results are displayed, then click Next.
On the Columns tab, customize the columns for displaying the results, then click Next.
On the Filter tab, narrow the results of your query using the drop-down list, then click Run.
You obtain a customized chart with the threat intelligence information from your TIE services.