From ePO - Is there any way I can find Event ID 1203 (which is for On-Demand Scan) without running any query, is this possible?
I have already gone through KB87752 & KB86702.
Solved! Go to Solution.
Priority event forwarding only means what events are sent immediately vs being sent at event forwarding interval, so it is not necessary to change your priority to informational. Informational events aren't sent as they occur, but at every 5 minutes by default. So, as long as you have enabled the event in ENS policy, you should be getting those events. Just make sure that event is enabled under server settings, event filtering.
Run a query for both threat and client events for that event id and see if it returns any data.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Events will be stored in database. To find them, we need to query.
If you are trying to look at a specific system for it, you can go to that system details and show threat events. However, that also runs a query. What exactly are you trying to accomplish without running a query and why can't a query be run?
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
VirusScan used to show ODS event ID in threat events from the system details .... it's no longer available from ePO if you have Endpoint Security. I was looking for a quick way to find out without running a query.
Look at KB87752. You have to enable that in the ens policy.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thanks, I already mentioned about this KB and another KB in my original posting.
problem is that this KB is asking you to change Agent setting to below under [McAfee Agent > General >Event]
"Click the Events tab and set Priority event forwarding to Informational."......
I'm using "Major" currently and I don't want change it.
Priority event forwarding only means what events are sent immediately vs being sent at event forwarding interval, so it is not necessary to change your priority to informational. Informational events aren't sent as they occur, but at every 5 minutes by default. So, as long as you have enabled the event in ENS policy, you should be getting those events. Just make sure that event is enabled under server settings, event filtering.
Run a query for both threat and client events for that event id and see if it returns any data.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA