Hello everyone,
I'm working on setting up McAfee Endpoint Security OAS exclusions for our Splunk environment, and I'm not seeing much success in keeping the mfetpd process from pretty much cratering these systems
I've reviewed the exclusion list provided by Splunk, but that does not seem to be of much help. Would anyone be willing / able to share their list of exclusions they use? The document from Splunk I used can be found here. I find it unfortunately a bit tough to do the process exclusions since from what I've experienced in OAS is they have to be exact to the path without any wildcards.
Solved! Go to Solution.
Hi @User91972758 ,
Yes, you should be able to use just process names.
Here's another KB that explains how to test a low risk exclusion.
https://kc.mcafee.com/corporate/index?page=content&id=KB93410&locale=en_US
Hope this helps.
Thanks
Hi @User91972758 ,
You may also add Splunk Process as Low Risk under On-Access Exclusion. Adding path ensures the process is only excluded if it matches the path. Its also possible to just add process names.
Please read more about it in the links below.
1) Why some processes must be added to low-risk exclusions
https://kc.mcafee.com/corporate/index?page=content&id=KB66036
2) Understanding High-Risk, Low-Risk, and Default processes configuration and use
https://kc.mcafee.com/corporate/index?page=content&id=KB55139
Thanks
Hi @User91972758 ,
Yes, you should be able to use just process names.
Here's another KB that explains how to test a low risk exclusion.
https://kc.mcafee.com/corporate/index?page=content&id=KB93410&locale=en_US
Hope this helps.
Thanks
In case any others had any questions, Pravas was correct. You can just exclude by process name. For example, I actually ended up having to exclude the dbssensor process because OAS was scanning it. Which is the processed used for the McAfee Database Activity Monitor application.
I was able to verify this worked by reviewing the threat events recorded in ePO and looking at the threat target process name which was used.
Once I added the exclusion I sent a wake-up call to my systems with the newly updated policy, and checked my hourly report I had previously made, and the alerts went from a couple of thousand down to 2, due to me having not woken a system up.
Thanks again @Pravas for your assistance in providing information to further clarify this, it was much appreciated!
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA