Hello, came across some strange thing... ePO 5.10, agent 5.6 Ens 10.6.1
Access protection user defined/custom rule if triggered is not appearing in epo. Ens common policy is configured to send back all events, epo server settings configured to accept id 1092, 1094 and 1095. Ens reports this rule locally AND agent sends the event 1095 to ePO according to agent logs. However, event can never be found on epo itself.
If its not a user defined rule, then event Id 1095 is shown in epo.
Has anyone seen this before? Problem is there must be thousands events like this never reported back. Rule when defined is set to report etc, but it seems like epo either discards it or never processes these events..
Solved! Go to Solution.
That was pretty much the case, agent was creating duplicate entries. However, the main thing was that sql dB wasn't set to English, in our case it was British English. Because of that events were going into epo debug folder, coz it couldn't properly parse them. Once language was changed events started coming in. After that agent was hotfixed and dB cleaned with an sql script. Thanks to mcafee support engineers its all sorted now
There are 3 logs you can look at for potential failures.
c:\programdata\mcafee\agent\logs - masvc log on the client will show if there were any failures sending the event to epo
c:\program files (x86)\mcafee\epolicy orchestrator\db\logs
server log will show it getting events from the client (or logs on agent handler if it is talking to an agent handler instead of epo).
eventparser log will show any errors parsing events.
If you are running the 5.6.0.878 version of the agent, that has an issue with possible flooding of events that can also cause this. You can either downgrade the agent to the rtw version of the 5.6 agent, or call in to get hotfix to resolve that. If you are experiencing that issue, you might need to call in anyway to get assistance clearing out the millions of events that get sent in.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
That was pretty much the case, agent was creating duplicate entries. However, the main thing was that sql dB wasn't set to English, in our case it was British English. Because of that events were going into epo debug folder, coz it couldn't properly parse them. Once language was changed events started coming in. After that agent was hotfixed and dB cleaned with an sql script. Thanks to mcafee support engineers its all sorted now
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA