Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create an operating system group

Operating system groups are used to map an operating system to specific process types and scripts in Security Incident Response workflows. The scripts define how running processes for the defined operating system groups are retrieved. New operating systems can be added as needed.

Before you begin

Role required: sn_sec_cmn.admin

Procedure

  1. Navigate to All > Security Operations > Utilities > Operating System Groups.

    The base system includes scripts for three operating systems:

    • BSD-based OS
    • POSIX-based OS
    • Windows OS
    • Select New.
Image omitted: os-groups.png
Operating system groups
  1. Fill in the fields, as needed.

    FieldDescription
    NameThe name of the operating system group.
    DescriptionA description for the operating system group.
    TableThe affected table.
    ActiveSelect this check box to activate the operating system group.
    Use filter groupSelect this check box to use a filter group for locating matching records in the selected table.
    Filter groupSelect the filter group for locating matching records in the selected table. This field displays only if you selected the Use filter group check box.
    ConditionThe condition builder fields display only if you did not select the Use filter group check box.
  2. Select and hold (or right-click) in the form header and select Save.

    The Operating System Related Scripts related list opens.

Image omitted: os-related-scripts.png
Operating System Related Scripts
  1. Select New.

  2. Select scripts that correspond with the workflows you're using to get running processes, services, and/or network statistics.

  3. Select Submit.

Parent Topic:Security Operations common functionality

Related topics

Attach a script file to a file synchronized MID Server