cancel
Showing results for 
Search instead for 
Did you mean: 

Access Protection User Defined Rules issue reporting ePO

Jump to solution

Hello, came across some strange thing... ePO 5.10, agent 5.6 Ens 10.6.1

Access protection user defined/custom rule if triggered is not appearing in epo. Ens common policy is configured to send back all events, epo server settings configured to accept id 1092, 1094 and 1095. Ens reports this rule locally AND agent sends the event 1095 to ePO according to agent logs. However, event can never be found on epo itself.

If its not a user defined rule, then event Id 1095 is shown in epo.

Has anyone seen this before? Problem is there must be thousands events like this never reported back. Rule when defined is set to report etc, but it seems like epo either discards it or never processes these events.. 

1 Solution

Accepted Solutions

Re: Access Protection User Defined Rules issue reporting ePO

Jump to solution

That was pretty much the case, agent was creating duplicate entries. However, the main thing was that sql dB wasn't set to English, in our case it was British English. Because of that events were going into epo debug folder, coz it couldn't properly parse them. Once language was changed events started coming in. After that agent was hotfixed and dB cleaned with an sql script. Thanks to mcafee support engineers its all sorted now

2 Replies
McAfee Employee cdinet
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Access Protection User Defined Rules issue reporting ePO

Jump to solution

There are 3 logs you can look at for potential failures. 

c:\programdata\mcafee\agent\logs - masvc log on the client will show if there were any failures sending the event to epo

c:\program files (x86)\mcafee\epolicy orchestrator\db\logs

server log will show it getting events from the client (or logs on agent handler if it is talking to an agent handler instead of epo). 

eventparser log will show any errors parsing events. 

If you are running the 5.6.0.878 version of the agent, that has an issue with possible flooding of events that can also cause this.  You can either downgrade the agent to the rtw version of the 5.6 agent, or call in to get hotfix to resolve that.  If you are experiencing that issue, you might need to call in anyway to get assistance clearing out the millions of events that get sent in.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Access Protection User Defined Rules issue reporting ePO

Jump to solution

That was pretty much the case, agent was creating duplicate entries. However, the main thing was that sql dB wasn't set to English, in our case it was British English. Because of that events were going into epo debug folder, coz it couldn't properly parse them. Once language was changed events started coming in. After that agent was hotfixed and dB cleaned with an sql script. Thanks to mcafee support engineers its all sorted now

More McAfee Tools to Help You

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community