I need to generate a report showing all the users and groups that have access to the SIEMs, and what priviledges they have. I know how to query AD, but not the actual SIEMs\ESM device. Isn't there a generic out-of-the-box report for this? Or a View that I could use?
Solved! Go to Solution.
rth67,
I opened a ticket with McAfee concerning this over two weeks ago, and I just heard back from them yesterday. This option isn't available...
There isn't currently a way to generate a report that list the users, groups, and what access\priviledges these users\groups have. So right now, it's screen print only.
I will need to submit a PER, so hopefully it will be in the next update. (Not likely)
Sux!!!
Message was edited by: pepelepuu on 5/21/14 2:15:46 PM CDTIf you find anything please let me know, we are wanting to do ongoing access review for our Security Devices, and it would be nice to be able to easily generate a report to show at minimum what groups have what privileges, if needed, I can generate something elsewhere to show who belong to the AD Groups that are mapped to the SIEM.
rth67,
I opened a ticket with McAfee concerning this over two weeks ago, and I just heard back from them yesterday. This option isn't available...
There isn't currently a way to generate a report that list the users, groups, and what access\priviledges these users\groups have. So right now, it's screen print only.
I will need to submit a PER, so hopefully it will be in the next update. (Not likely)
Sux!!!
Message was edited by: pepelepuu on 5/21/14 2:15:46 PM CDTI am building out a spreadsheet, and manually going through each AD mapped Group to document what access they have.
I will submit a PER also, the more PER's they have on a given topic from multiple customers, the more likely they are to do something.
I definitely agree
Hi Pepelepuu, Did you ever hear anything back from McAfee on your PER?
I hope so. Producing a list of SIEM users and their access is a requirement of PCI, I would have though this would be a standard canned Compliance report. This manually updated spreadsheet method is going to be a pain to maintain. (and I don't think the auditor is going to be thrilled with it either)
It's 2020 and there still doesn't seem to be an option to run this type of report. Has anyone seen otherwise? I feel like this is a such a simple function to have, how could McAfee not have something like this in place?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA