Extend Operations Management Suite security with your own notable issues
Summary: Learn how to create your own notable issues to accommodate your specific business needs.
Operations Management Suite (OMS) Security and Audit solution highlights notable security issues. Administrators should be aware of and examine these issues. Some issues are common, such as standard configuration changes that can occur as part of the normal business cadence. Others are rare events that might indicate a malicious activity, such as detecting a security log deletion.
OMS Security and Audit solution has lots of built-in notable issues. While they are a good start, many organizations might like to extend and add their own notable issues that represent their specific logic or unique set of priorities.
You can turn any OMS search query into a Security and Audit notable issue by saving it to one of the three unique saved searches categories:
- Security Critical Notable Issues
- Security Warning Notable Issues
- Security Info Notable Issues
After you save a query to a category, it appears in the notable issues area in the Security and Audit solution.
Here is a quick step-by-step guide:
- Start on the OMS search page. From this page, you can also examine the preconfigured notable issues.
- After you define the query, save it to one of the notable issues categories:
- From now on, the new query will appear in the notable issues list:
- If you want to delete this query later, just go to the search start screen and delete it from the list:
Note that you can’t delete or edit the preconfigured notable issues.
Comments
- Anonymous
April 21, 2016
good stuff - how do you do this in generic way i.e. whats the Query syntax. Couldn't find it in the syntax documentation.- Anonymous
April 26, 2016
Lars, check here: https://technet.microsoft.com/library/mt450427.aspx
- Anonymous