cancel
Showing results for 
Search instead for 
Did you mean: 
peterz
Level 8
Report Inappropriate Content
Message 1 of 12

e-mail notification virus infection

Jump to solution

How can I be informed (via email) quickly when a virus has been found on a client.

Is that also the agent-to-server communication every 60 minutes?

1 Solution

Accepted Solutions
taziegma
Level 10
Report Inappropriate Content
Message 5 of 12

Re: e-mail notification virus infection

Jump to solution

The McAfee Agent has various event priorities that are used when client or threat events are generated. By default, events of severity Major or above are sent within five minutes. You can customize this in your McAfee Agent General policy. Malware events should be seen as Major events and sent within five minutes. The Automatic Response monitors for new events and then triggers when new events are available.

11 Replies
Unblack
Level 10
Report Inappropriate Content
Message 2 of 12

Re: e-mail notification virus infection

Jump to solution

we use the Automatic Responses in the epo server.

Example filter: Threat Category belongs to Malware

peterz
Level 8
Report Inappropriate Content
Message 3 of 12

Re: e-mail notification virus infection

Jump to solution

How often "talks" the epo sever with the clients.

Is the "automatic responses" interval not equal to the agent-to-server communication-interval (default every 60 minutes)?

Unblack
Level 10
Report Inappropriate Content
Message 4 of 12

Re: e-mail notification virus infection

Jump to solution

No. Automatic Responses use events that occur on systems.

McAfee KnowledgeBase - ePolicy Orchestrator 5.3.0 Produkthandbuch

taziegma
Level 10
Report Inappropriate Content
Message 5 of 12

Re: e-mail notification virus infection

Jump to solution

The McAfee Agent has various event priorities that are used when client or threat events are generated. By default, events of severity Major or above are sent within five minutes. You can customize this in your McAfee Agent General policy. Malware events should be seen as Major events and sent within five minutes. The Automatic Response monitors for new events and then triggers when new events are available.

kmc
Level 12
Report Inappropriate Content
Message 6 of 12

Re: e-mail notification virus infection

Jump to solution

Hi @

peterz

You need to create a automatic response like below

Description section

1.) Create a new Automatic Response

2.) Name it

3.) Event Group: ePO Notification Events

4.) Event type: threat

Under the Filter tab

** filter the values like systems you want to monitor systems and threats you want to monitor handled, not handled**

select filter for detecting product == VSE

Under aggregation:

you can chose to alert for every event or define threshold as per you convince  

Under action:

Select send emial and fill the details and provide template

Example:

ePolicy Orchestrator Notification

Response Name: {responseRuleName}

Event Type Name: {responseEventType}

Defined at: {definedAt}

System Location: {nodeTextPath}

Description: Sends an e-mail notification when "Malware detected and handled" events are received.

Number of events: {count}

Source IPV6 addresses: {sourceIPV6}

Source IPV4 addresses: {sourceIPV4}

Threat Names: {threatName}

Detecting Product Names: {analyzerName}

you are good go then

Regards,

KMC

peterz
Level 8
Report Inappropriate Content
Message 7 of 12

Re: e-mail notification virus infection

Jump to solution

Thank you all.

Highlighted
mkazi
Level 9
Report Inappropriate Content
Message 8 of 12

Re: e-mail notification virus infection

Jump to solution

what value should i add to see what action has been taken ?

McAfee Employee cdinet
McAfee Employee
Report Inappropriate Content
Message 9 of 12

Re: e-mail notification virus infection

Jump to solution

:Threat action taken" and any other values desired to get more info on it.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

mkazi
Level 9
Report Inappropriate Content
Message 10 of 12

Re: e-mail notification virus infection

Jump to solution
This is what i setup, does it look okay ?
Number of events: {count}
Source IPV4 addresses: {sourceIPV4}
Affected system(s): {listOfAnalyzerHostName}
Target files: {listOfTargetFileName}
Threat Names: {threatName}
Action Taken: {threatActionTaken}
Detecting Product Names: {analyzerName}
More McAfee Tools to Help You

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community