nCircle VERT Blog

IP360 Reporting Filters 101 - Part II

Last week I discussed how to use IP360 reporting filters to exclude or include a list of IP addresses when generating a report. This week I am going to show you how to create a report consisting of only hosts with a specific operating system class. For example, let's walk through the process for creating a report filter that generates a report of only Windows hosts.

First, navigate to 'Analyze -> Reporting Filters' and click 'New' to create a new reporting filter. Give your filter a name such as "Windows Hosts Only" and proceed to the 'OS Groups' tab. Next, select the 'Include' action and double-click 'nCircle: Windows' from the available list. The selection will move over into the selected box. You can now click 'Add', and the filtering rule will appear below. Now that you have completed the filter, click 'Submit' to save.

filter.png

Now that your filter is complete, you can apply it to any report you are generating to restrict the hosts in the report to Windows boxes only.

If you wish to create your own OS Group, or modify existing ones, you can navigate to 'Analyze -> OS Groups' and either click on 'New' or select an existing filter to view it. In existing filters such as 'nCircle: Windows' you see the operating system tree for Windows is a different colour than the other operating systems in the list, as these are the ones currently selected. Selecting a parent will create a group that includes all of that parent's children.

filter.png


TrackBack

TrackBack URL for this entry:
http://blog.ncircle.com/cgi-bin/mt-tb.cgi/426


About

This page contains a single entry from the blog posted on September 27, 2011 2:22 PM.

The previous post in this blog was Apache HTTP Server Range Header Denial Of Service Vulnerability.

The next post in this blog is Using Virtual Applications to Maintain Large Scale Environments .

Many more can be found on the main index page or by looking through the archives.



Bio

Blog: VERT
Author: nCircle VERT

nCircle VERT is the research team behind nCircle, continuously publishing updates for nCircle IP360 and nCircle's family of products. VERT conducts deep research across a broad class of network security intelligence, creating unique, agentless detection for: vunerabilities, host configurations, applications, services, user accounts, operating systems, and other network security conditions. Members of the group use this blog to share their opinions on the security industry, emerging threats, technology trends, and the world at large.


   




Categories