Multi-server rollup querying

Prev Next

ePO - On-prem includes the ability to run queries that report on summary data from multiple databases.

Use these result types in the Query Builder for this type of querying:

  • Rolled-Up Threat Events

  • Rolled-Up Client Events

  • Rolled-Up Compliance History

  • Rolled-Up Managed Systems

  • Rolled-Up Applied Policies

  • Rolled-Up Users Audit

Action commands cannot be generated from rollup result types.

How it works

To roll up data for use by rollup queries, you must register each server (including the local server) that you want to include in the query.

Once the servers are registered, you must configure Roll Up Data server tasks on the reporting server (the server that performs the multi-server reporting). Roll Up Data server tasks retrieve the information from all databases involved in the reporting, and populate the EPORollup_ tables on the reporting server. The rollup queries target these database tables on the reporting server.

As a prerequisite to running a Rolled-Up Compliance History query, you must take two preparatory actions on each server whose data you want to include:

  • Create a query to define compliance.

  • Generate a compliance event.