Hi Team,
We have alert provides only the details of Network intrusion detected and handled/ blocked events (Event ID:18001), we require the Event ID of unhandled IPS events also. Please advise us on how to get the events for Network intrusion detected unhandled ?
Hello @Praveen459113
Will it be possible for you to be more specific, what do you mean by "... we require the Event ID of unhandled IPS events also."?
Is this something to the effect of, HIPs detects network intrusion, but was unable to block it for any gives reason, similar to the events we have for VSE where threat can be detected, but not cleaned or deleted at that time?
Because if that is what you are looking for, that type of event doesn't exist, please refer to:
*** List of Host Intrusion Prevention 8.0 event IDs
https://kc.mcafee.com/corporate/index?page=content&id=KB65559
Here you may find all events HIPs generates with their names and Event IDs.
I hope this helps.
HI There,
Thank you for the KB article, Event ID 18001 is for Network intrusion detected and handled like wise do we have event ID for Network intrusion not handled so that it will east for us to track the intrusions that are handled by HIPS
Is this something to the effect of, HIPs detects network intrusion, but was unable to block it for any gives reason, similar to the events we have for VSE where threat can be detected, but not cleaned or deleted at that time? Yes, HIP detects network intrusion but unable to block .
Hello @Praveen459113
As I mentioned in original post, that type of event doesn't exist.
All events related to HIPs are listed in the KB65559 and your event is not one of them.
I hope this helps.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA