Here are instructions for EPO 4.5 (may differ slightly for EPO 4.0):
- Logon to ePO console
- Navigate to Menu | Reporting | Queries
- Click New Query
- Select Others for Feature Group and DLP Events for Result Types | Next
- Select Table | Next
- Remove all of the selected columns and add the following*:
- Computer Name
- User Name
- Destination
- Evidence Type
- Evidence value
- Click Next
- Add the filter Event Type | Equals | DLP: Removable Storage Protection
- Click Run and confirm you have the results you are looking for. If so click Save | Give the report a name and select a group to store it in | Click Save.
* You may want different columns these are just the ones that made sense to me given what you wish to query. The actual file name will be stored in the Evidence value column.
No comments:
Post a Comment
Please Use Good Leanguage