6 Replies Latest reply on Feb 11, 2009 1:31 PM by nscott

    ePO 4.0 On-Demand Scan Report

      Is it possible to run a report to show on which machines a scheduled on-demand scan has actually run? In other words, is it possible to run a report on ePO tasks based on info from the Agents?
        • 1. RE: ePO 4.0 On-Demand Scan Report
          I too would love to hear if anyone has any insight on this issue.
          • 2. Report for ODS
            Hi all
            First of all, you must enable event with ID 1203 in "Event Filtering".
            Download from following link file and import to query repository. This query will help to find machines reported about ODS scan complete over time. Query created on ePO4 patch 3. If you find way to make some improvements, share it please.

            http://rapidshare.com/files/192329540/Query_VSE_ODScomplete.zip.html


            Alex
            • 3. RE: Report for ODS
              The link is dead. Can you post the XML for the query?
              • 4. RE: Report for ODS
                Here is the XML

                <queries>
                <query>
                <name language="iw">VSE: ODS complete</name>
                <description language="iw"></description>
                <property name="target">EPOEvents</property>
                <property name="tableURI">query:table?orion.table.columns=EPOEvents.DetectedUTC%3AEPOEven ts.TargetHostName%3AEPOEvents.TargetIPV4%3AEPOEvents.ThreatCategory%3AEPOEvents. ThreatEventID&amp;orion.table.order=az&amp;orion.table.order.by=EPOEvents.Detect edUTC%3AEPOEvents.TargetHostName%3AEPOEvents.TargetIPV4%3AEPOEvents.ThreatCatego ry%3AEPOEvents.ThreatEventID</property>
                <property name="conditionURI">query:condition?orion.condition.sexp=%28+where+%28+eq+EPOEv ents.ThreatEventID+1203++%29+%29</property>
                <property name="summaryURI">query:summary?orion.show.other.limit=0&amp;orion.sum.order.by =EPOEvents.DetectedUTC&amp;orion.show.other=false&amp;orion.sum.group.by=EPOEven ts.ThreatEventID&amp;orion.sum.aggregation.column=EPOEvents.DetectedUTC&amp;orio n.sum.time.cols=false&amp;orion.sum.aggregation=distinct&amp;orion.sum.order=des c&amp;orion.sum.limit.count=0&amp;bar.title=EPOEvents.ThreatEventID&amp;orion.ch art.type=bar&amp;orion.sum.limit=false&amp;orion.sum.query=true</property>
                </query>
                </queries>
                • 5. RE: Report for ODS
                  Like he said before. Make sure you enable event 1203 in event filtering.

                  Configuration...Server Settings...Event Filtering...Edit
                  • 6. RE: Report for ODS
                    Thanks!