Log Search with Steve: Some helpful FIM Dashboards to help

Hey all,
If you have FIM configured and turned on in your IDR (it’s under settings), feel free to take a peak at some dashboard queries I made. Most of them are modeled around Windows, so if there is a need for more Linux queries, just drop a comment and I’ll see if I can come up with anything nice. These are just some basic ideas, so please adjust them as needed, also don’t forget to adjust any timeslice values so they match properly with your time picker:

image

I know this is probably impossible to read, right click save image and then you should be able to open it and view it normally, cheers!

4 Likes

Thanks Stephen, it is a great job!
Could you also give some Linux queries pls?

1 Like

@maltindal,

Sorry for the severe delay in this, let me dig up my linux queries and I’ll post them up for you.

1 Like

Thanks Stephen,very cool.

1 Like

Hi Stephen.
Do you have some idea to create a Linux query that show all applications/programs installed?
For instance: apache, java, oracle…including also the software version, example: v1.8.0.392

Thanks in advanced for your help!!
Cross

Hi @cross2024 this would be something that our InsightVM product would be more suitable for, with process starts in Log Search you can only be sure that a process ran, you cannot say if a program is installed with certainty.

David