cancel
Showing results for 
Search instead for 
Did you mean: 
pumar
Level 7
Report Inappropriate Content
Message 1 of 2

Automatic Responses for Threat events

Hey all,

I need some help.

I need an automatic response when at a client within 30 minutes, the event id 19115 (Device_PLUG) appears more than 5 times. How should it be done. Which Filter and Aggregation has to be defined?

At the moment I get mails, although the event only once per client appears.

Thanks for your help.

1 Reply
McAfee Employee hhoang
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: Automatic Responses for Threat events

Sounds like you are looking for aggregation.  'Trigger this response if multiple event occur within: 30 minutes' and 'When the number of events is at least: 5'

Grouping:  Group aggregated events by 'Machine name'

Throttling would control how often the email notification would be sent.  Device plug events can be generated fairly frequently depending on driver behavior so you may want to be careful setting that to something low.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community