Upgraded from 5.1.1 to 5.3.1. Afterwards most (only 5 out of 35 windows systems) are reporting threat events from HIPS. and only those 5 are showing Firewall/IPS etc as enabled on the dashboard. But if you look at the server then you see that it is listed as enabled. They are using the same policy so its not a policy issue...
ePO 5.3.1 latest Hotfix
HIPS 8.0 Patch 8
Not sure why or what is causing this....not seeing anything in the logs. Have removed HIPS and reinstalled....do see event ID 1119 Update failed. See log but that seems to be VSE but it looks like it occurs around the same time the events quit populating.
Any help appreciated.
The current HIPS 8.0 version does not have functionality to log firewall events to ePO. You will have to go local to the system and review the HIPS Activity log (in the HIPS ClientU - McAfeeFire.exe) for blocked/allowed Firewall events. Please submit a PER if you'd like to request this functionality in a future version.
KB60021 - Information about Product Enhancement Requests for McAfee products
Workaround is Using TAT see below doc.
Can you check the following
"D:\Program Files\Mcafee\Epolicy orchestrator\DB\Logs\EventParser.log" do you see this entry ?
Server_ProcessXMLFile: Failed to create parser extension for <HostIPS8>