Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Filtering Device Rules by User or Group

SUMMARY In JSA Risk Manager, you can view and filter your device rules by user or group.

Search by user or group rule interaction, and get a sense of how the typical user or group interacts in your network. Knowing your users' rule interactions in your network is helpful in discovering any errant behavior, and helps to formulate efficient rule policies in your network.
  1. Click the Risks tab.
  2. On the navigation menu, click Configuration Monitor.
  3. From the Device List table, double-click the table row for your device, and view your users and groups.

    Group results are displayed with hyperlinks to view the users in the selected group.

  4. From the Rules pane, click Search > New Search.
  5. Click Select Users/Groups.
  6. Type a partial or full search term or leave the User/Group Name field empty, and then click Search.
  7. Select the user or group name in the Search Results field, and then click Add, to add your selections to the Selected Items box.
  8. Click OK, and then click Search.

    Use the rule information to establish benchmarks or profiles for user rule interaction, which can be used to optimize rule policies in your network.