Hi,
In Insight, with version 6.10.7 we've got a number of alerts defined under the "Total Authentication" template.
We are showing login records which have certain roles. This works. But the "drill down" for the alert only shows Timestamp, ClearPass server, MAC, User, and result.
This is insufficient. It makes no sense to have alert filters containing 5 pages of filter terms, while keeping us with only 5 columns of data.
Can I make a new template that has multiple other fields? Maybe remove the CPPM server, and add device UDID, or something else from the connection, endpoint, or certificate?
Thanks,
Ambi
------------------------------
Ambidexter
------------------------------