Working with events
Integrity Monitor provides two sensors to view events:
- Integrity Monitor File Events Overview: Includes columns for each event are process path, file path, user, change type, date, hour, minute group, detail. The Integrity Monitor Current Results page uses this sensor. Once you have deployed a monitor, you can view resulting events by selecting that monitor and clicking Current Results.
- Integrity Monitor File Events Details: Includes columns for each event are time stamp, process path, file path, user, change type, detail, watchlists. This sensor is available to use in Saved Questions in Tanium™ Connect.
When an endpoint has no resulting events, the event sensors will display No integrity violations found.
If [no results] is displayed, there is an error on the endpoint. Ask a question with the Integrity Monitor Endpoint Tools Status sensor in Interact to identify the error. See Asking questions for more information. See Reference: Endpoint monitoring status errors for help in resolving the error.
- When viewing a monitor’s current events, you can create a rule from an event by selecting that event and clicking Learn Event.
- On the Create Rule page, the Rule Criteria fields will be pre-populated with criteria from the event you selected.
- Complete the other necessary fields and click Create.
To learn more about rules, see Working with rules.
Use labels to annotate alarms as you review results to mark action that needs to be taken on an event.
Following is the default label configuration in Integrity Monitor:
The labels Important and Suspicious are configured to notify Connect. You will see the Connect icon next to these labels.
Integrity Monitor provides shortcuts to labels using the number keys, assuming you have less than 10 labels. Each number corresponds to the order of the labels as they are listed across. For example, if Expected is the third label across in the list, then, if you hit the 3 key with a row selected, that row will automatically be labeled Expected. Hitting the 3 key again, while the row is selected and once it is labeled, will remove the Expected label.
Use rules to enable auto-labeling and get notified of events of concern. See Working with rules.
Remove a label from an event
To remove a label from an event, simply follow the steps to apply the same label to that event. Select the event and then select the label from the Label drop-down list.
- Click settings at the top right of the Integrity Monitor Home page.
- Click the Labels tab.
- Click Edit Default Labels to change the label Name, Color, or Description. You can also specify whether or not that label is included in the results information sent by Connect. Any changes to default labels will affect every Monitor.
If you modify default labels, you will not be able to return to the default definitions.
- Click Edit Custom Labels next to a monitor to change the labels just for that monitor. Use delete to delete any unnecessary labels.
Create a new label from a monitor page
- Select the event you want to label.
- From the Label drop-down menu, select Create Label.
- In the Create Label window, provide a Name for the label, specify a Color, and add an optional Description. Select Notify Connect if you want events with this label included in results information sent to Connect.
- Click Save.
Add notes to labels
You can add notes to labeled events to provide additional information, such as action being taken.
To add a note to an existing label and apply it to an event
- On the monitor page, select the event(s) in the results table to which you want to apply the label.
- From the Label drop-down menu, select Label with Note.
- In the Label with Note window, select the label you want to apply from the Label drop-down menu.
- Enter a note in the Note field.
- Click Save.
- Once a label with a note is applied to an event, a note icon appears with the label. You can mouse over the icon to see the note.
Remove a note from a label
To edit a note or remove it from a label, modify the Note field in the Label with Note window to edit it or clear the Note field to remove the note.
Using the Label History tab
Integrity Monitor deletes labeled events from the label history after 30 days.
Integrity Monitor will store up to 1 million labeled events. When you exceed 1 million labeled events, Integrity Monitor deletes the oldest labeled events to bring the total count back down to 1 million. Labeled events are kept for at least 72 hours after they are created, regardless of if the total count is greater than 1 million in that time period.
If reporting is enabled for a monitor and you exceed 1 million labeled events before the report is scheduled to run, Integrity Monitor will delete the oldest labeled events to bring the total count back down to 1 million. A new report will be created that includes events since the last report and any events that have been deleted.
On the monitor page, click Manage Labels. This will take you to the Settings page. Follow the steps in Customize labels to edit labels.
- From the Home page or the Monitors page, either Create a New Monitor or select an existing monitor.
- Click the Reports tab.
- If you want to stop reporting at any time for a specific monitor, click Disable reporting for this monitor on the right side of the page.
- To see reports for a monitor, select the monitor and click the Reports tab. Reports are listed showing the most recent one first. A report will show all label events for the defined weekly report interval. Columns in the report for a monitor match the label history for that monitor.
- Download a report as a zipped CSV file using the Download link or delete a report by clicking delete .
Example 1: Reports run on Sunday at midnight. On Tuesday, you change the report to run on Wednesday at midnight. The first report on Wednesday will cover 3 days.
Example 2: Reports run on Sunday at midnight. On Thursday, you change the report to run on Wednesday at midnight. The first report on Wednesday will cover 10 days.
Setting Weekly Report Schedule
By default, when you choose to run reports for a monitor, they are run every Sunday at 12:00 AM UTC. To change this default value
- On the Integrity Monitor Home page, click settings at the top right to go to the Settings page.
- On the General Settings tab, change the Day of the Week and Time fields to the Weekly Report Schedule you want for all reports.
- Once you have results, click Send all events to Connect at the top right of the page. This will use events from the Integrity Monitor File Events Details sensor.
- Click Yes in the Create Connection window. The connection is created with the Integrity Monitor File Events Details saved question for that monitor as the source and results are sent to a .csv file using the file destination via Connect.
- Under All events connection at the top right of the page, click Edit to go to Connect to modify the connection.
- Once in Connect, you can change anything in the configuration such as the Destination.
For more information about Connect, refer to the Connect User Guide.
Use the main menu to navigate back to Integrity Monitor.
Under All events connection, click Delete to remove the connection.
Send only labeled events
- Click Label events connection at the top right of the results table. Labels marked with a icon are configured to be sent via Connect. This will use events from the Integrity Monitor File Events Details sensor. The same options (View, Edit, and Delete) are available for this function as well. The connection is created with the events enabled for that monitor as the source, and results are sent to a .csv file using the file destination via Connect.
- Click Send Data Now. A check mark will appear in the column to confirm that an alarm is being sent via Connect.
Send labeled events at defined intervals
- Click settings at the top right of the Home page.
- Click the General Settings tab.
- Under Background Process Settings, click Enable to send labeled events to Connect.
- Adjust the Labeled Event Sync Interval to define a regular time interval that Integrity Monitor sends labeled results to Connect and that Connect sends out these labeled results. The default value is 30 minutes.
- Click Save.
Provide your Service Credentials and click Yes to begin the background process.
Last updated: 10/23/2018 2:42 PM | Feedback