Symantec IGA

 View Only
  • 1.  Identity Governance: Config Compare as Business Report

    Posted Apr 01, 2020 12:31 PM

    Good afternoon

    We have a customer that would like to use the IG DIFF report for business reporting. They would like to run this daily to check for users that have been assigned sensitive access. They would like this report generated and exported from within the IG console, preferably on a schedule.

    We can generate the audit cards to display this data, but these cannot be exported. The DIFF report described in the link does not present in a form that business users can use without intervention.


    Has anyone had this requirement before or know of how this information can be drawn from the system?

    Kind regards,

    Muzi Lubisi

    IG Compare Operation:

    https://techdocs.broadcom.com/content/broadcom/techdocs/us/en/ca-enterprise-software/layer7-identity-and-access-management/identity-governance/14-3/client-tools/manage-configurations-and-databases/compare-operations.html



  • 2.  RE: Identity Governance: Config Compare as Business Report

    Broadcom Employee
    Posted Apr 02, 2020 10:47 AM
    We're not sure what is meant by "DIFF report." Perhaps you can provide more info. Scheduling reports, however, are not available and would require an enhancement that you can request in the Ideas site.

    ------------------------------
    Perhaps there are others in the communities who have experience in doing this and we invite them to comment here also.

    Another option may be to reach out to our partner HCL Technologies to see in what way they can assist further. The Enterprise Studio team of HCL can be reached at enterprisestudio@hcl.com. https://www.hcltech.com/enterprise-studio
    ------------------------------



  • 3.  RE: Identity Governance: Config Compare as Business Report

    Posted Apr 03, 2020 01:08 AM

    Good morning

    This file/report is generated via the procedure described in the link. It compares the Master Model configuration files and picks up any differences, e.g. users, resources or resource links. This is done in the IG Discovery & Audit tool(app).

    Kind regards

    Muzi




  • 4.  RE: Identity Governance: Config Compare as Business Report

    Broadcom Employee
    Posted Apr 03, 2020 02:26 AM
    This cannot be done OOTB. As Ricky said, you will probably need to go for the solution Ricky suggested to use Kettle.

    ------------------------------
    ------------------------------
    And, as always Perhaps there are others in the communities who have experience in doing this and we invite them to comment here also.
    Another option may be to reach out to our partner HCL Technologies to see in what way they can assist further. The Enterprise Studio team of HCL can be reached at enterprisestudio@hcl.com. https://www.hcltech.com/enterprise-studio
    ------------------------------



  • 5.  RE: Identity Governance: Config Compare as Business Report

    Posted Apr 03, 2020 03:24 AM
    Good morning

    Agreed, I will try the suggestion and see how far we can take it. 

    Kind regards
    Muzi


  • 6.  RE: Identity Governance: Config Compare as Business Report
    Best Answer

    Posted Apr 02, 2020 04:16 PM
    A diff is usually a method of comparing 2 configs such as master vs model.  
    Depending on how you are maintaining the master/model, this could be meaningless.  
    If you are maintaining master/model sync, then the report will be empty: which you don't want.
    If you are not maintaining master/model sync, then the report will be cumulative, which you don't want.  

    I would likely create a solution outside of the IG toolset using Kettle.
    - download the current model to file.
    - compare to yesterday's (previous) file and create report
    - rotate files (move current to previous)
    - schedule to run daily.


  • 7.  RE: Identity Governance: Config Compare as Business Report

    Posted Apr 03, 2020 03:24 AM
    Hi Ricky

    Thanks for the suggestion, let me try this and see how far I get.

    Kind regards
    Muzi