Datenbankansicht für Symantec System Center konfigurieren
Das JDBC -Protokoll benötigt eine Datenbankansicht, um SSC-Ereignisse abzufragen.
Vorgehensweise
CREATE VIEW dbo.vw_qradar AS SELECTdbo.alerts.Idx AS idx,dbo.inventory.IP_Address AS ip,dbo.inventory.Computer AS computer_name,dbo.virus.Virusname AS virus_name,dbo.alerts.Filepath AS filepath,dbo.alerts.NoOfViruses AS no_of_virus,dbo.actualaction.Actualaction AS [action],dbo.alerts.Alertdatetime AS [date],dbo.clientuser.Clientuser AS user_name FROMdbo.alerts INNER JOINdbo.virus ON dbo.alerts.Virusname_Idx = dbo.virus.Virusname_Idx INNER JOINdbo.inventory ON dbo.alerts.Computer_Idx = dbo.inventory.Computer_Idx INNER JOINdbo.actualaction ON dbo.alerts.Actualaction_Idx =dbo.actualaction.Actualaction_Idx INNER JOINdbo.clientuser ON dbo.alerts.Clientuser_Idx = dbo.clientuser.Clientuser_Idx