Reports

適用於: Operations Manager 2007 R2

To view Cross Platform ACS reports, start your browser and navigate to http://<yourReportingServerName>/Reports.

The following table of reports describes audit events for UNIX-based and Linux-based computers.

Cross Platform ACS Reports

Report Name Description File Name

Unsuccessful Logon Attempts on All Monitored UNIX-Based and Linux-Based Computers

For UNIX-based and Linux-based computers, this report shows unsuccessful logon attempts and the source of each attempt for all monitored computers. Large numbers of unsuccessful logon attempts for the same user or computer may indicate a potential intrusion.

Unix_Access_Violation_-_Unsuccessful_Logon_Attempts.rdl

Account Management on All Monitored UNIX-Based and Linux-Based Computers

For UNIX-based and Linux-based computers, this report identifies accounts that have been created, deleted, and modified.

Unix_Account_Management.rdl

Privileged Logons on All Monitored UNIX-Based and Linux-Based Computers

This report shows logons for the root user on all monitored UNIX-based and Linux-based computers.

Unix_Privileged_Logon.rdl

Administrator Activity on All Monitored UNIX-Based and Linux-Based Computers

This report shows logons for the root user on all monitored UNIX-based and Linux-based computers.

Unix_Administrator_Activity.rdl

All Events for a Specified User on All Monitored UNIX-Based and Linux-Based Computers

This report shows all events associated with the specified user within the specified time range on all monitored UNIX-based and Linux-based computers. It is used for general investigation of a specified user account. To tailor the report for a specific investigation, use SQL Server Report Builder to modify the report parameters to add string and header fields or to change filter criteria.

Unix_Forensic_-_All_Events_For_Specified_User.rdl

All Events for a Specified UNIX-based or Linux-based Computer

This report shows all events associated with a specified computer within a specified time range on all monitored UNIX-based and Linux-based computers. It is used for general investigation of event activity. To tailor the report for a specific investigation, use SQL Server Report Builder to modify the report parameters to add string and header fields or to change filter criteria.

Unix_Forensic_-_All_Events_For_Specified_Computer.rdl

All Events for a Specified Event ID on all Monitored UNIX-based and Linux-based Computers

This report shows all events associated with a specified event ID within a specified time range on all monitored UNIX-based and Linux-based computers. It is used for general investigation of event activity. To tailor the report for a specific investigation, use SQL Server Report Builder to modify the report parameters to add string and header fields or to change filter criteria.

Unix_Forensic_-_All_Events_For_Specified_Event_ID.rdl