Upgraded from 5.1.1 to 5.3.1. Afterwards most (only 5 out of 35 windows systems) are reporting threat events from HIPS. and only those 5 are showing Firewall/IPS etc as enabled on the dashboard. But if you look at the server then you see that it is listed as enabled. They are using the same policy so its not a policy issue...
MA 5.0.4.449
ePO 5.3.1 latest Hotfix
HIPS 8.0 Patch 8
Not sure why or what is causing this....not seeing anything in the logs. Have removed HIPS and reinstalled....do see event ID 1119 Update failed. See log but that seems to be VSE but it looks like it occurs around the same time the events quit populating.
Any help appreciated.
Hi
The current HIPS 8.0 version does not have functionality to log firewall events to ePO. You will have to go local to the system and review the HIPS Activity log (in the HIPS ClientU - McAfeeFire.exe) for blocked/allowed Firewall events. Please submit a PER if you'd like to request this functionality in a future version.
KB60021 - Information about Product Enhancement Requests for McAfee products
https://kc.mcafee.com/corporate/index?page=content&id=KB60021
Workaround is Using TAT see below doc.
https://community.mcafee.com/docs/DOC-4231
Thanks,
Syed
ok thanks...that explains the Firewall however I am not getting IPS events....Any thought on those?
V/R,
David
Hi David,
Can you check the following
"D:\Program Files\Mcafee\Epolicy orchestrator\DB\Logs\EventParser.log" do you see this entry ?
Server_ProcessXMLFile: Failed to create parser extension for <HostIPS8>
Thanks,
Syed
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA