ePO - On-prem includes the ability to run queries that report on summary data from multiple databases.
Use these result types in the Query Builder for this type of querying:
Rolled-Up Threat Events
Rolled-Up Client Events
Rolled-Up Compliance History
Rolled-Up Managed Systems
Rolled-Up Applied Policies
Rolled-Up Users Audit
Action commands cannot be generated from rollup result types.
How it works
To roll up data for use by rollup queries, you must register each server (including the local server) that you want to include in the query.
Once the servers are registered, you must configure Roll Up Data server tasks on the reporting server (the server that performs the multi-server reporting). Roll Up Data server tasks retrieve the information from all databases involved in the reporting, and populate the EPORollup_ tables on the reporting server. The rollup queries target these database tables on the reporting server.
As a prerequisite to running a Rolled-Up Compliance History query, you must take two preparatory actions on each server whose data you want to include:
Create a query to define compliance.
Generate a compliance event.