Perform a Rolled-Up User Audit across multiple ePO servers

Prev Next

Rolled-Up User Audit in ePO - On-prem allows administrators to collect and view user login and audit information from multiple ePO servers in a single reporting server. This helps you monitor and report on user accounts and login activity across your environment.

Before you begin:
  • Ensure all ePO servers are running supported versions.

  • Register all target ePO servers under MenuConfigurationRegistered Servers.

  • Ensure user audit data (such as logins, password changes) is available on the source servers.



  1. Create (or Modify) a Roll-Up Data Server Task for User Audit.

    1. Open the Server task Builder page and select MenuAutomationServer Tasks.

    2. Click New Task.

    3. (alternatively) To modify the default Roll up Data (Local Trellix ePO server) server task:

      1. Locate the Roll up Data (Local Trellix ePO server) server task in the list.

      2. Click Edit under Actions column.

    4. On the Description page, type a name for this task (for example, "User Audit Rollup"), add notes, and select whether to enable it, then click Next.

    5. From the Roll up data from: drop-down menu, select All registered servers or Select registered servers.

    6. If you chose Select registered servers, click Select. Choose the servers you want data from in the Select Registered Servers dialog box, then click OK.

    7. In the Data Type dropdown, select Users Audit, then click Next.

      Note

      The Users Audit data type can be further configured to include Purge option, which allows you to remove old audit records before retrieving new data. To do so, click Configure in the row that describes the Purge property.

    8. Schedule the task, then click Next.

      The Summary page appears.

    9. Review the settings, then click Save.

    10. Run the task immediately or wait for it to run based on the schedule.

  2. Create a Query to view Rolled-Up User Audit data.

    1. Navigate to MenuReportingQueries & Reports, then click New Query.

    2. On the Result Type page, go to Roll-Up Targets and select Rolled-Up Users Audit.

    3. Select a chart type (For example, Table, Bar Chart, Pie Chart).

    4. Add relevant columns and filters.

    5. Save the query.

    6. On the Queries & Reports page, search for the query that you created and click Run to preview the results.

  3. Create a query to retrieve the local ePO user data

    1. Navigate to MenuReportingQueries & Reports, then click New Query.

    2. On the Logging page, select User Audit.

    3. Select a chart type (For example, Table, Bar Chart, Pie Chart).

    4. Add relevant columns and filters.

    5. Save the query.

  4. You can now see the registered servers displayed in the form of a chart.

  5. Click on a particular registered server to see the list of users data such as name, last logon time, last password changed.