Retrieving metadata from a paired Endpoint Security Server

Prev Next

You can retrieve usernames associated with hostnames on-demand in the NDR Web UI for one IP address at a time. IP address and hostname information is automatically indexed when the NDR syncs up with the server. To configure how often indexing occurs, see Changing NDR and Endpoint Security server configuration settings after integration.

To retrieve usernames from an Endpoint Security Server:

  1. In the NDR Web UI, search for the IP address of the paired server you want to filter metadata from.

  2. Scroll to the Event Table in the Dashboard.

  3. Above the Event Table, in the button panel, click the Edit Columns button. For more information about the Event Table, see the "The Dashboard" chapter of the NDR Series User Guide.

  4. Select destinationHostName or sourceHostName from the list of filters. The option you select appears as a new column in the Event Table.

  5. In the destinationHostName or sourceHostName column, click the caret next to the hostname you want.

  6. Click getUsername. A pop-up window appears with the username associated with the hostname indexed from the server appliance.