Solved! Go to Solution.
In order to assign one group of user the permission of run ODS task you will have to make sure the permission set has
1. Endpoint Security Threat Prevention : Tasks has the View and change settings
2. Systems: View "System Tree" tab
3. System Tree access: Can search on the following nodes and portions of the System Tree:My Organization
Can access the following nodes and portions of the System Tree:My Organization
The on demand scan log should show start and stop times for it.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Run client task now depends on several things.
1. Active system to receive the task at the time it is sent
2. RCTN task might have a time limit set on it - check for that.
3. There must be no data channel communication failures in the server log on the epo server or agent handlers.
You can check the server log for errors or the client logs (masvc agent log) to see if it received the task.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Assuming this is for ENS, you would probably need to give them permissions for modifying tasks and policies for the point product as well as system tree access under system tree and systems. Otherwise you would have to check audit log to see, when testing, if they are missing any other permissions.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
In order to assign one group of user the permission of run ODS task you will have to make sure the permission set has
1. Endpoint Security Threat Prevention : Tasks has the View and change settings
2. Systems: View "System Tree" tab
3. System Tree access: Can search on the following nodes and portions of the System Tree:My Organization
Can access the following nodes and portions of the System Tree:My Organization
Thank you for your quick response. It is truly appreciated. Here is what I have determined:
When I added the 3 permission changes that you listed below, only the “Modify Task” option was available. The option to do a “Run Task Now” was not available. But your information was very helpful.
Once I added the permission to allow “Wake up agents; view Agent Activity Log ”, I was able to select a server or workstation, choose “Actions”, then “Agent” then “Run Client Task Now”, which allowed me to choose “Endpoint Security Threat Prevention”, and complete a Custom On Demand Scan or a Policy Based On Demand Scan.”
I could also choose On-Demand Scan – Full or On-Demand Scan – Quick Scan
I would then be presented with the “Running Client Task Status” screen.
The Full Scan seems to take quite some time. I am checking to see if this is related to a Policy Setting
Can you please tell me the best way to validate the start time and completion time for a Full On Demand scan? I could not locate this directly in the ENS Log files (in %ProgramData%
Once again, thank you for your outstanding assistance.
That's a wonderful share and Kudos to you for sharing your knowledge and marking the answer as solution. This will help other community users with similar question to find answer
The on demand scan log should show start and stop times for it.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
That should be present under <C:\ProgramData\McAfee\Endpoint Security\Logs>. As cdinet mentioned, you can either check the details in logs or if you would like to pull those information via ePO, you can create a custom query to pull information like "On-Demand scan start" ""On-Demand scan stop", by quering event id's.
https://kc.mcafee.com/corporate/index?page=content&id=KB54677
Was my reply helpful?
If you find this post useful, please give it a Kudos! Also, please don't forget to select "Accept as a Solution" if this reply resolves your query!
Thank you. I was able to determine the Log file location. Much appreciated. The remaining issue is this:
I have a two Client Tasks setup for the purpose of running an On Demand Quick Scan and an On Demand Full Scan. In testing, when I run these manually from within EPO, I am getting inconsistent results. Sometime the scan will complete, but most of the time it fails. Now when it runs as as an automated scheduled Client Task, it runs fine. Since this is happening in two different EPO environments, I may simply open a Support Call to McAfee.
I have to get this functionality in place for second level support. I will check the McAfee Community, but if you are aware of a possible fix, I would be grateful for your response.
Thank you.
Run client task now depends on several things.
1. Active system to receive the task at the time it is sent
2. RCTN task might have a time limit set on it - check for that.
3. There must be no data channel communication failures in the server log on the epo server or agent handlers.
You can check the server log for errors or the client logs (masvc agent log) to see if it received the task.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA