We are not seeing any ATP events under Reporting or Dashboards. Is this normal if observe mode is checked in the policy? I should at least see observed events right? Or is there another reason for why no events are present. Everything is configured and working as far as DXL & TIE are concerned. Find it odd no events reporting.
Solved! Go to Solution.
Hi @kblowe
Many thanks for posting on the Community.
I would be very surprised if you weren't seeing any events generated however to force one, you can use the Real-Protect Test Files: https://kc.mcafee.com/corporate/index?page=content&id=KB88828
One in-built Dashboard is called: Endpoint Security: Adaptive Threat Protection Observed Events - this dashboard should be getting populated with your observation events.
If you aren't seeing any events at all, it might be worth checking that you are allowing the generation of these events. To do this, please navigate within your ePO server to Server Settings > Event Filtering. You want to check that the events 35100 - 35107 are enabled.
If these are checked, then you can also check that within your McAfee Agent policy you aren't just forwarding Major events. You may need to select a lower event level i.e. Informational
Hi @kblowe
Many thanks for posting on the Community.
I would be very surprised if you weren't seeing any events generated however to force one, you can use the Real-Protect Test Files: https://kc.mcafee.com/corporate/index?page=content&id=KB88828
One in-built Dashboard is called: Endpoint Security: Adaptive Threat Protection Observed Events - this dashboard should be getting populated with your observation events.
If you aren't seeing any events at all, it might be worth checking that you are allowing the generation of these events. To do this, please navigate within your ePO server to Server Settings > Event Filtering. You want to check that the events 35100 - 35107 are enabled.
If these are checked, then you can also check that within your McAfee Agent policy you aren't just forwarding Major events. You may need to select a lower event level i.e. Informational
Events 35100 - 35107 are enabled and stored on ePO. Also the McAfee Agent>General policy Events are set to Minor. Could be issue with policy. I checked and the ENS Common policy didn't have Client Logging> Event Logging for ATP events to log: set at all. I set to warning,critical, and alert. Will monitor for events.
If you have any other steps, please let me know.
Hi @kblowe
You may need to set the Event Level within ePO Forwarding to Informational. If you still don't see any events, please do try this. And as I said, if you want to force event generation so you can check quicker then you can use the Real Protect Test Files.
But if you didn't have ATP Events within ENS Common Policy enabled, then you may have already found the problem 🙂
Just a FYI, I was seeing events up until a month ago. I changed to Informational and that didn't make a difference. I downloaded the Test File to generate a event and that worked as it should. The events showed in under ATP events as blocked.
My question now is maybe the ATP policy is not strict enough. I have "Endpoint Security Adaptive Threat Protection : Policy Category > Options" set to Productivity under Rule Assignment. Which by default the Action Enforcement is "Trigger Dynamic Application Containment when reputation threshold reaches: Most Likely Malicious" and "Block when reputation threshold reaches: Known Malicious". Is it better to keep the Rule Assignment at "Balanced" or it depends on the organization. Because currently no events are happening and we not not in observe mode. Any insight would be helpful. Thanks.
Hi @kblowe
Thank you for sharing feedback. I am glad you received events once forced with the Test File - at least that proves that you do have everything set up correctly.
We recommend keeping the default configuration. Of course you can change these settings if you want, this is your choice and I urge caution and would advise only applying the policy as a test to a certain sub-set of machines so you avoid any impact. If you change DAC to trigger when "Unknown" I would expect you to see a lot of events.
Thanks for the tips. I recreated the ATP Option policy and left at the default of Balanced instead of Productivity. I started noticing events slowly generating.
There is not much in the ATP guide on Threat Detection Messaging. I have the defaults below, but isn't that excessive, meaning it will send a message for every Unknown file to the user?
Display threat notifications to user The defaults when checked states: Notify the user when reputation threshold reaches: Unknown Default Action: Allow Specify length (minutes) of timeout: 5. Message: McAfee Endpoint Security detected a file with an unknown reputation.
Hi @kblowe
By default, ATP's specific Threat Detection User Messaging is actually disabled. You will still receive threat detection notifications in the form of a windows toast notification, the same as you would for a threat detected from On-Access Scan.
To directly answer your question though, yes this would generate a lot of noise/interruption for users if you have this setting enabled and set to trigger at unknown. The main benefit this feature provides is the ability to make users confirm that they want to run the unknown application (by selecting Allow in the notification) to give an extra bump towards thinking about what they're running on the machine. But, like I said, this will generate a lot of noise.
Hopefully that helps!
Hello, No enforce or observed events are generating for ATP at all now. I have reset a few polices, restarted the TIE server, and still nothing. Its like ATP is not enabled. Help!
Hi Kblowe,
Please tell me if you are using ePO ( On-Prem or MVSION-ePO/Cloud-ePO )
If you are using On-Prem then the events should be selectable from the event-id list from the server settings option event filtering.
If however you are using MVISION ePO or Cloud based ePO, events 35100-35107 are filtered out by the platform and at this stage cannot be enabled on either cloud based platform.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA