How can I be informed (via email) quickly when a virus has been found on a client.
Is that also the agent-to-server communication every 60 minutes?
Solved! Go to Solution.
The McAfee Agent has various event priorities that are used when client or threat events are generated. By default, events of severity Major or above are sent within five minutes. You can customize this in your McAfee Agent General policy. Malware events should be seen as Major events and sent within five minutes. The Automatic Response monitors for new events and then triggers when new events are available.
we use the Automatic Responses in the epo server.
Example filter: Threat Category belongs to Malware
How often "talks" the epo sever with the clients.
Is the "automatic responses" interval not equal to the agent-to-server communication-interval (default every 60 minutes)?
No. Automatic Responses use events that occur on systems.
McAfee KnowledgeBase - ePolicy Orchestrator 5.3.0 Produkthandbuch
The McAfee Agent has various event priorities that are used when client or threat events are generated. By default, events of severity Major or above are sent within five minutes. You can customize this in your McAfee Agent General policy. Malware events should be seen as Major events and sent within five minutes. The Automatic Response monitors for new events and then triggers when new events are available.
Hi @
You need to create a automatic response like below
Description section
1.) Create a new Automatic Response
2.) Name it
3.) Event Group: ePO Notification Events
4.) Event type: threat
Under the Filter tab
** filter the values like systems you want to monitor systems and threats you want to monitor handled, not handled**
select filter for detecting product == VSE
Under aggregation:
you can chose to alert for every event or define threshold as per you convince
Under action:
Select send emial and fill the details and provide template
Example:
ePolicy Orchestrator Notification
Response Name: {responseRuleName}
Event Type Name: {responseEventType}
Defined at: {definedAt}
System Location: {nodeTextPath}
Description: Sends an e-mail notification when "Malware detected and handled" events are received.
Number of events: {count}
Source IPV6 addresses: {sourceIPV6}
Source IPV4 addresses: {sourceIPV4}
Threat Names: {threatName}
Detecting Product Names: {analyzerName}
you are good go then
Regards,
KMC
Thank you all.
what value should i add to see what action has been taken ?
:Threat action taken" and any other values desired to get more info on it.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA