Con risposta FEP Reports are just plain bad or...

  • giovedì 29 dicembre 2011 18:29
     
     
    How can I generate a report to show which machines have a certain malware detected?  If I go to the computer details report, I can see who had activity but if i attempt to filter it out by malware name, I get zero hits!  Whats the proper syntax (if any) to use here.  If this isnt the right place to get that data, where is?  A sql report perhaps?

Tutte le risposte

  • venerdì 30 dicembre 2011 07:32
    Moderatore
     
     

    Hi,

    Thank you for your post.

    Please try to run Malware reports in http://localhost/ReportServer --FEP--Antimalware, like Malware Details Report.

    If there are more inquiries on this issue, please feel free to let us know.

    Regards,


    Rick Tan

    TechNet Community Support

  • venerdì 30 dicembre 2011 14:02
     
     
    Do you have to use the exact name?
  • venerdì 30 dicembre 2011 14:09
     
     
    Ok you do have to use the exact name, but that report does not give me a list of machines that have a specific malwar, it just gives me the details of said malware.
  • martedì 3 gennaio 2012 06:27
    Moderatore
     
     Con risposta

    Hi,

    I can see who had activity but if i attempt to filter it out by malware name, I get zero hits!
    I test it on my server, it show computers infected this malware when you click the malware name.

    Do you have to use the exact name?
    Run the Top Malwares Summary Report, select the Start Date and End Date.


    Top Malwares Summary Report layout:

    Malware Name     Category   Severity   Computers    First Detection
    Malware A             Virus      Severe      9                   XX-XX-XXXX 

    When you click the Malware Name link(like Malware A), it will link to Malware Details Report.

    Malware Details Report layout:
    Malware Details
    ...
    Antimalware Activity
    ...
    Infected COmputers
    Computer Name   Protecton Status  ....
    Computer A          ...
    Computer B          ...
    ...

    Regards,


    Rick Tan

    TechNet Community Support



  • mercoledì 4 gennaio 2012 17:39
     
     
    Rick, I get this Error:Subreport could not be shown.  Seems I have something not working properly.  Thanks for your help thus far, and I am curious where to go next.
    • Modificato mottm mercoledì 4 gennaio 2012 19:53
    •  
  • giovedì 5 gennaio 2012 01:47
    Moderatore
     
     Con risposta

    Hi,

    To the error, please try to verify if KB2554364 installed or check solution in this thread. Good luck.

    Regards,


    Rick Tan

    TechNet Community Support


    • Modificato Rick TanModerator giovedì 5 gennaio 2012 01:48
    • Contrassegnato come risposta mottm lunedì 20 febbraio 2012 15:27
    •  
  • lunedì 20 febbraio 2012 15:27
     
     
    By adding the -q switch in SQL and setting an upper limit of 512k, this resolved our subreport issue.