cancel
Showing results for 
Search instead for 
Did you mean: 
peterz
Level 8

e-mail notification virus infection

Jump to solution

How can I be informed (via email) quickly when a virus has been found on a client.

Is that also the agent-to-server communication every 60 minutes?

0 Kudos
1 Solution

Accepted Solutions
taziegma
Level 10

Re: e-mail notification virus infection

Jump to solution

The McAfee Agent has various event priorities that are used when client or threat events are generated. By default, events of severity Major or above are sent within five minutes. You can customize this in your McAfee Agent General policy. Malware events should be seen as Major events and sent within five minutes. The Automatic Response monitors for new events and then triggers when new events are available.

0 Kudos
6 Replies
Unblack
Level 10

Re: e-mail notification virus infection

Jump to solution

we use the Automatic Responses in the epo server.

Example filter: Threat Category belongs to Malware

0 Kudos
peterz
Level 8

Re: e-mail notification virus infection

Jump to solution

How often "talks" the epo sever with the clients.

Is the "automatic responses" interval not equal to the agent-to-server communication-interval (default every 60 minutes)?

0 Kudos
Unblack
Level 10

Re: e-mail notification virus infection

Jump to solution

No. Automatic Responses use events that occur on systems.

McAfee KnowledgeBase - ePolicy Orchestrator 5.3.0 Produkthandbuch

0 Kudos
taziegma
Level 10

Re: e-mail notification virus infection

Jump to solution

The McAfee Agent has various event priorities that are used when client or threat events are generated. By default, events of severity Major or above are sent within five minutes. You can customize this in your McAfee Agent General policy. Malware events should be seen as Major events and sent within five minutes. The Automatic Response monitors for new events and then triggers when new events are available.

0 Kudos
kmc
Level 12

Re: e-mail notification virus infection

Jump to solution

Hi @

peterz

You need to create a automatic response like below

Description section

1.) Create a new Automatic Response

2.) Name it

3.) Event Group: ePO Notification Events

4.) Event type: threat

Under the Filter tab

** filter the values like systems you want to monitor systems and threats you want to monitor handled, not handled**

select filter for detecting product == VSE

Under aggregation:

you can chose to alert for every event or define threshold as per you convince  

Under action:

Select send emial and fill the details and provide template

Example:

ePolicy Orchestrator Notification

Response Name: {responseRuleName}

Event Type Name: {responseEventType}

Defined at: {definedAt}

System Location: {nodeTextPath}

Description: Sends an e-mail notification when "Malware detected and handled" events are received.

Number of events: {count}

Source IPV6 addresses: {sourceIPV6}

Source IPV4 addresses: {sourceIPV4}

Threat Names: {threatName}

Detecting Product Names: {analyzerName}

you are good go then

Regards,

KMC

0 Kudos
peterz
Level 8

Re: e-mail notification virus infection

Jump to solution

Thank you all.

0 Kudos