cancel
Showing results for 
Search instead for 
Did you mean: 

Log entries disappear after deletion of system from ePO

Hello.

Is this normal (doesn't seem like it should be)?

Deleted a system from ePO that had been decomissioned and all log entries in Threat Event and HIPS are now gone as well.  Obviously we'd like to keep that information.

Any ideas or help is greatly apprecaited.

Thank you.

-Todd

7 Replies
McAfee Employee hem
McAfee Employee
Report Inappropriate Content
Message 2 of 8

Re: Log entries disappear after deletion of system from ePO

I apologize but I am not able to reproduce it. The event should not be deleted once machine is deleted from the server.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?please select Accept as Solution in my reply and together we can help other members?
McAfee Employee JoeBidgood
McAfee Employee
Report Inappropriate Content
Message 3 of 8

Re: Log entries disappear after deletion of system from ePO

The events certainly shouldn't be deleted, but it's possible you may not be able to see them any more   (I realise that sounds like a nonsense sentence but bear with me.)

I assume that you can no longer see events for the deleted machine in the results of queries - is that correct? If so, are you logged on as a global admin user when you run the query? If not, try the query under a global admin account - do you see the results again?

There's a scenario where deleted machine events are hidden from non-global-admin users - I'm wondering if that's what's happening here...

HTH -

Joe

Re: Log entries disappear after deletion of system from ePO

Joe,

Thanks for the reply.  That would make sense.  Howerver, I am logged in as a Global Admin, so.

It's not even just running a query (just looking at the Threat Event Logs (which is 'technically' a query of sorts I guess) it doens't show up.  The only place it shows up after deletion is in the Audit Logs where it shows me deleting it.

Very frustrating.

McAfee Employee JoeBidgood
McAfee Employee
Report Inappropriate Content
Message 5 of 8

Re: Log entries disappear after deletion of system from ePO

Odd     There's not really any filtering on the threat event log that should be hiding anything like this...

If you write a very simple query to search for threat events from that particular machine name, is anything shown?
Do you have access to the SQL Management Studio and are you happy running queries directly against the ePO database?

Thanks -

Joe

Re: Log entries disappear after deletion of system from ePO

So, it get's even more weird.  Client events query shows the system.  Threat Events does not.

I do have access to the SQL Management Studio.  What would the correct query for that be?

Thanks for the help.

-Todd

McAfee Employee JoeBidgood
McAfee Employee
Report Inappropriate Content
Message 7 of 8

Re: Log entries disappear after deletion of system from ePO

Okay, that makes sense - at least it implies that there's no deliberate removal of events when a machine is deleted. (If there were, we'd be removing the product events as well.)

To see if there are any threat events at all for this machine, you could try the following query against the ePO database:

SELECT * FROM ePOEvents WHERE AnalyzerHostName = 'XXXXX'

where XXXXX is the name of the machine. (Make sure it is enclosed in the single quote marks.)  If you run this query does it return anything at all?

Thanks -

Joe

Re: Log entries disappear after deletion of system from ePO

Yes.  It does.  Even more bizzare now.  Ugh.  At least things are still there.

More McAfee Tools to Help You

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community