Skip to main content

Policies reports

User class errors

Purpose: Lists user class configuration error; for example, where a PSLang expression could not be evaluated.

Executable: ucerrors

Table 1. User class errors report search criteria

Criteria

Description

User class ID

Type the User class ID to list its information.

Policies where the user class can be referenced

Select one or more user class policy points to include in the report. All user class policy points are included by default.

Display errors only

Select this checkbox to display errors only.



The report output contains the following columns:

Column

Description

User class ID

The user class identifier.

User class description

The description of the user class.

Actor

The actor type in the user class.

Configuration item

The configuration item that caused the error.

Result

The error result or message.

User class members

Purpose: Lists membership in single participant user classes. Relational user classes are not included.

Executable: ucmember

Table 2. User class members report search criteria

Criteria

Description

Single-participant user classes

Select one or more single-participant user classes. All single-participant user classes are included by default.

Policies where the user class can be referenced

Select one or more user class policy points to include in the report. All user class policy points are included by default.

Do not display built-in user classes

Enable this checkbox to exclude built-in user classes, which are hard-coded. For example, _USER_IS_MANAGER_ is built-in.

Summarize report

Select this checkbox to summarize the report details.

Minimum number of user class members

The minimum number of user class members allowed to display. This option will only display when Summarize report is selected.

Maximum number of user class members

The maximum number of user class members allowed to display. This option will only display when Summarize report is selected.



The report output depends on whether the Summarize report option is selected.

Detailed mode

When Summarize report is not selected, the report contains the following columns:

Column

Description

User class ID

The user class identifier.

User class description

The description of the user class.

Actor

The actor type.

Actor description

The description of the actor.

User ID

The profile ID of the member.

User name

The full name of the member.

Summary mode

When Summarize report is selected, the report contains the following columns:

Column

Description

User class ID

The user class identifier.

User class description

The description of the user class.

Actor

The actor type.

Member count

The number of members.

User classes

Purpose: Lists configuration, use and cache status of user classes.

Executable: userclasses

Table 3. User classes report search criteria

Criteria

Description

User class ID

Type the User class ID to list its information.

Policies where the user class can be referenced

Select one or more user class policy points to include in the report. All user class policy points are included by default.

Date user class created

(Optional) Choose a date range for the user class creation.



The report output contains the following columns:

Column

Description

User class ID

The user class identifier.

User class description

The description of the user class.

Participation point

The participation point of the user class.

Date created

The date the user class was created.

Validity

The validity status of the user class.

Validity date

The date the validity was last checked.

User access privileges

Purpose: Security privileges granted to users.

Executable: userpriv

Table 4. User access privileges report search criteria

Criteria

Description

Requester ID

Type the ID of the user whose privileges you want listed. Alternatively, you can search for one or more profile IDs.

Allowed privileges

Select one or more privileges to display. All privileges are included by default.

Rules

Select which set of user access rules to generate the report for:

  • Global help desk rules

  • Self-service rules

  • Delegated administration rules: You must enter the profile ID of the Recipient.

Recipient

Type the profile ID of the recipient for whom you want to run the report.



The report output contains the following columns:

Column

Description

User ID

The profile ID of the user.

User name

The full name of the user.

Privilege

The access privilege name.

Description

The description of the privilege.

Entitlement review privileges

Purpose: The link between reviewers and users they are allowed to review.

Executable: adhoccertificationprivileges

Table 5. Entitlement review privileges

Criteria

Description

Options

Select to:

  • List reviewers for selected users

  • List users who can be reviewed by selected reviewers

Users to be reviewed

This option is displayed if List reviewers for selected users is selected. Type a comma and space delimited list of user profile IDs to list the possible reviewers for these users. Alternatively, you can search for one or more user profile IDs

Reviewer ID

The option is displayed List users who can be reviewed by selected reviewers is selected. Type a comma and space delimited list of reviewers' profile IDs to list the users who can be reviewed by these reviewers.



The report output depends on the selected option.

By reviewable user

When List reviewers for selected users is selected, the report contains the following columns:

Column

Description

Reviewable user ID

The profile ID of the user whose entitlements can be reviewed.

Reviewable user name

The full name of the reviewable user.

Certifier ID

The profile ID of the certifier.

Certifier name

The full name of the certifier.

Rule description

The description of the user access rule that grants the review privilege.

By certifier

When List users who can be reviewed by selected reviewers is selected, the report contains the following columns:

Column

Description

Certifier ID

The profile ID of the certifier.

Certifier name

The full name of the certifier.

Reviewable user ID

The profile ID of the user whose entitlements can be reviewed.

Reviewable user name

The full name of the reviewable user.

Rule description

The description of the user access rule that grants the review privilege.

Authentication chains

Purpose: Authentication chains configuration and usage statistics. Lists the results (successes and failures) of authentication chains.

Executable: authchain

Table 6. Authentication chains report search criteria

Criteria

Description

Authentication chain

Select one or more authentication chains to include in the report.

Status

Select the authentication chain status to include in the report:

  • (All): authentication chains are included in the report regardless of their status

  • Success: authentication chains are only included in the report if they have "Success" status

  • Failure: authentication chains are only included in the report if they have "Failure" status

User ID

Type the profile ID of the user for whom you want to generate the report. By default, all users are included. Alternatively, you can search for one or more profile IDs.

Choose relative date

(Optional) Choose a date range for authentication chain initiation.

Show detailed report

Select this checkbox to display additional report details.

Graph type

Select the graph type:

  • (None): No graph generated

  • Vertical bar chart: bar chart will be generated

  • This option is only shown when Show detailed report is not checked.



The report output depends on the Show detailed report option.

Detailed mode (drill-down)

When Show detailed report is selected and a specific authentication chain is clicked, the drill-down report contains the following columns:

Column

Description

User

The user who authenticated (combined name and profile link).

Event time

The date and time of the authentication event.

Detailed mode (non-drill-down)

When Show detailed report is selected, the main report contains the following columns:

Column

Description

Authentication chain ID

The identifier of the authentication chain.

User ID

The profile ID of the user.

Event time

The date and time of the authentication event.

Result

The result of the authentication attempt.

IP address

The IP address from which the authentication was attempted.

Summary mode

When Show detailed report is not selected, the report contains the following columns:

Column

Description

Authentication chain ID

The identifier of the authentication chain.

Description

The description of the authentication chain.

Successful

The number of successful authentications.

Failed

The number of failed authentications.

Policy configuration

Purpose: Displays the policy configuration stored in the external database.

Executable: dumppolicyconfiguration

Table 7. Policy configuration report search criteria

Criteria

Description

Table

Choose a table in the external database.

Format

Choose:

  • Tabular: Display the report in a table format.

  • Transposed: Display the report as a list of key-value pairs.

Omit Blank

Choose "Yes" to omit blank rows/columns.



The report output depends on the selected Format option.

Table format

When Tabular is selected, the columns are dynamic — one column per policy configuration field. The columns displayed depend on the selected policy table.

Transposed format

When Transposed is selected, the report contains the following columns:

Column

Description

Field

The policy configuration field name.

Value

The value of the configuration field.

Question set configuration

Purpose: Provides information on pre-defined question sets, question set usage, and users who have populated question sets.

Executable: questionsetinformation

Table 8. Question set configuration report search criteria

Criteria

Description

Report type

Select:

  • List question sets

  • Question set usage summary

  • Question usage details

  • Users with answers to question sets

Question set

List all enabled pre-defined question sets.

Question status

List all question statuses (Answered and/or Unanswered). This option is only shown when Question usage details is selected.

User ID

For reports on users with answers to question sets, type the profile ID of the user for whom you want to generate the report. By default, all users are included. Alternatively, you can search for one or more profile IDs.

Graph type

Select the graph type:

  • (None): No graph generated

  • Horizontal bar chart: bar chart will be generated

This option is only shown when Question usage summary is selected.

Number of rows for graph

The maximum rows for graph to display. The selected rows will be displayed with the number of questions in descending order.



The report output depends on the selected Report type.

Question sets

When List question sets is selected, the report contains the following columns:

Column

Description

User

The user (combined name and profile link).

Last modified date

The date the question set answers were last modified.

Question usage

When Question set usage summary is selected, the report contains the following columns:

Column

Description

Question set

The question set identifier.

Description

The description of the question set.

Question usage details

When Question usage details is selected, the report contains the following columns:

Column

Description

Question set

The question set identifier.

Description

The description of the question set.

Question

The question text.

Users answered

The number of users who answered this question.

Users' answers

When Users with answers to question sets is selected, the report contains the following columns:

Column

Description

User ID

The profile ID of the user.

User name

The full name of the user.

Question set

The question set identifier.

Description

The description of the question set.

Question

The question text.

Answered

Whether the user answered this question.

Question set members

The question set members report contains the following columns:

Column

Description

Question set

The question set identifier.

Description

The description of the question set.

User ID

The profile ID of the user.

User name

The full name of the user.

Explicit user class members

Purpose: Track when a user class membership (explicit users) is added/removed.

Executable: usersexplicit

Criteria

Description

User class ID

Type the User class ID to list its information.

User ID

Type the profile ID of the user for whom you want to generate the report. By default, all users are included. Alternatively, you can search for one or more profile IDs.

Operations on explicit users

Choose the operation type for explicit user class members:

  • Add explicit user as the user class member (UMAD).

  • Delete explicit user as the user class member (UMDE).

Added/deleted in last N days

Specify a certain number of past days for the report to search within.

The report output contains the following columns:

Column

Description

User class ID

The user class identifier.

User class description

The description of the user class.

User ID

The profile ID of the explicitly added member.

User name

The full name of the member.

Operation code

The operation code (add or remove).

Operation description

The description of the operation.

Operation date

The date the operation was performed.

User class overlap

Purpose: Identifies user classes with overlapping user populations.

Executable: userclassoverlap

Table 9. User class overlap report search criteria

Criteria

Description

Compare these user classes

Type the user class ID or a comma-and-space-delimited list of user class IDs for which you want to analyze the overlapping membership against all selected user classes to generate the report. You can not leave this box empty. Alternatively, you can search for one or more user class IDs.

… to these user classes

Type the user class ID or a comma-and-space-delimited list of user class IDs against which you want to compare to generate the report. By default, this box is empty and all user classes but the built-in ones are included. Alternatively, you can search for one or more user class IDs.

Overlap (%)

Type the overlap threshold that is used to add user classes to the output if their membership overlap meets or exceeds the threshold. Its range is 1-100 and by default it is set to 75%.



The report output contains the following columns:

Column

Description

User class ID (1)

The identifier of the first user class.

User class description (1)

The description of the first user class.

Overlap

The number of overlapping members between the two user classes.

User class ID (2)

The identifier of the second user class.

User class description (2)

The description of the second user class.

Overlap (2)

The number of overlapping members from the second user class perspective.