Filtering Device Rules by User or Group
In JSA Risk Manager, you can view and filter your device rules by user or group.
Search by user or group rule interaction, and get a sense of how the typical user or group interacts in your network. Knowing your users' rule interactions in your network is helpful in discovering any errant behavior, and helps you in formulating efficient rule policies in your network.
- Click the Risks tab.
- On the navigation menu, click Configuration Monitor.
- From the Device List table, double-click the
table row for your device.
From the User(s)/Group(s) column in the rules table, you can view your users and groups.
Group results are displayed with hyperlinks, which you can click, to view the users in the selected group.
- From the Rules pane, click Search >New Search.
- Click Select Users/Groups.
- Type a partial or full search term or leave the User/Group Name field empty, and then click Search.
- Select the user or group name in the Search Results field, and then click Add, to add your selections to the Selected Items box.
- Click OK, and then click Search.
Use the rule information to establish benchmarks or profiles for user rule interaction, which can be used to optimize rule policies in your network.