Building Policies

Retrieving audit results from your servers requires that you schedule a Policy to run against it. Within this Policy are a number of constructs, including Filters and Rules. Each of these constructs performs a different role within AuditShark. These roles are described in the following sections.


A Rule is the fundamental building block of an AuditShark Policy. Rules may be combined to form Filters or in aggregate to form other Rules.


Filters are made up of one or more Rules. Filters may be part of a Policy and are primarily used to determine the prerequisites for running Rules on a target computer.


Functions are used inside of Rules to perform different actions


Variables are used inside of Rules as placeholders for data

