i would prefer the McAfee SIEM solution to connect to every supported EPO Server database.
You can use the "EPO Rollup Data" functionality, but there are two things you should thing about.
- RollUp Data does not cover any event in detail
- RollUp Data is not possible with every EPO Server version (my point of information
We did a internal POC with a 3rd Party software to forward the EPO threat events to one single system. The problem is, depending on the EPO server version and the extension version, the database entries are changing.
Thanks for the suggestion however there is no point us to purchase another product. Also SIEM is wide product I would require implementation within the business and integrate with current products we use.
We just need a little other functionality we currently have and I agree that SIEM could be best from logs / events perspective. Any suggestion how we can approach that with ePO and SQL server? Shall we push from each ePO or rather pull? Shall we copy full tables or just select columns. Many questions around ;-) Trying to find proof of concept.
Thanks for any suggestion here!
You can do it through ePO Roll Up Data option.
I may be wrong but you can try to add remaining all ePO server as registered server in ePO 5.1, where make sure you have all extensions added which other ePO servers are having.
2 x ePO 4.6
ePO 5.1 - Add other ePO servers as registered servers.
Few steps need to perform on 5.1 ePO console.
- Register all ePO server in 5.1 as registered ePO server. Menu > Configuration > Registered server, Where you need all ePO sitelist.xml file, SQL instance name and SQL admin authentication details.
- Create a new server task and select action as Roll Up Data and select all ePO server where schedule as daily one time.
- Now go to ePO queries and navigate to roll up data where you can create all required reports of all ePO in one single console.
Hope this will help.
This seems to be a great idea. I will dig in and get back here next week. We going to deploy Reporting ePO 5.1.1 shortly and will check that method out. Thanks ansarias
This perfectly works. Only one tip is to create new query - you need to chose Rolled-up Targets section and there you have Rolled-up options. Thanks for the help!