8 Replies Latest reply on Nov 5, 2010 2:59 AM by derluc10

    HIPS Events Lose Information after agent reinstall

      I'm seeing something odd and new when viewing recent HIPS events.  I have a dashboard that shows HIPS events for the last day by threat severity for our servers.  We group our servers by function within ePO so I have a second row that shows the same events but by group.  I've had some signatures trigger when exceptions have been created; it's an ongoing issue with that.  The hosts were not enforcing policy correctly so I forced a deployment of the ma to those hosts.  Immediately events disappeared from the dashboard.

       

      I've learned why they disappeared from view in the reports on the dashboard, but cannot figure out the cause of the change.  After I reinstalled the agent all of the events that were triggered prior lost the group information.  If i did a table report with a column for group it was blank up until events generated after the agent reinstall.  Since the queries in that dashboard are filtered by group those past events disappeared from those reports.

       

      Now, my question is what would cause some information, like the group and assignment path, to disappear from the event info after the ma is reinstalled?  And, is there a way to remediate it?

       

      This can be troublesome when I'm performing trending and analysis on specific groups.

       

      I've been researching this, but can't find a cause.

        • 1. Re: HIPS Events Lose Information after agent reinstall
          metalhead

          What is the HIPS extension version you are using ?

          • 2. Re: HIPS Events Lose Information after agent reinstall
            Kary Tankink
            Now, my question is what would cause some information, like the group and assignment path, to disappear from the event info after the ma is reinstalled?  And, is there a way to remediate it?

             

            I could be wrong (but your comments seem to support this), but this could be due to reinstalling the McAfee Agent and assigning a new GUID value to that particular node in the ePO database.  Events are tied to the node's GUID, and if that GUID is changing, it's technically a new node (even if the node's hostname is the same).  Check the node's McAfee Agent GUID and see if it's changing.  If you are completely uninstalling (or doing a /forceinstall) of the McAfee Agent, I do believe a new GUID will be assigned to the system.

             

            McAfee Agent GUID = unique node identifier value in the ePO database

            • 3. Re: HIPS Events Lose Information after agent reinstall

              We're running:

               

              HIPS     7.0.0.1070 Patch 6

               

              EXT.     7.0.4.105

               

              MA       4.5.0.1270

               

              ePO      4.0

              • 4. Re: HIPS Events Lose Information after agent reinstall

                I agree that the GUID may be the issue here.  But, it would seem ePO would record a snapshot of data at the time of the event; here are the statistics for the host when this triggered.  That would be the logical thing as far as forensics is concerned.  Maybe McAfee opted for another solution because of database storage concerns.

                 

                And, what if a host is removed from the network?  Would ePO say I don't have anything on this host because I can't find it?  I've never seen that.  My colleague and I are trying to remember if we've seen this happen before.  But, it appears to be a new development.

                 

                I was able to do more extensive testing because we manage several ePO servers on multiple networks.  The same thing happened across the board.  So, it is definitely something inherent in software, and not a 'glitch' on a particular ePO server.

                 

                The bigger issue overall is the problem where existing exceptions suddenly fail to work on some hosts.  It's something the McAfee engineers haven't been able to answer for us in the last six months.  It's been a big concern for us especially for servers.  If exceptions stop working on DCs or Exchange servers that becomes a major problem.  You can try altering an exception slightly, or deleting it and creating a new one.  Or reinstall HIPS (that poses another issue when some hosts fail to reinstall).  The drastic step is to remove everything, drop the host, then add it again and start over.

                 

                But, this missing host data is a concern when we're doing trending or looking at possible attacks on a certain group of hosts.  We get frequent requests to investigate newly discovered threats/vulnerabilities, so history beyond 24 hours is important for us.

                • 5. Re: HIPS Events Lose Information after agent reinstall
                  metalhead

                  I would try using the latest HIPS extension 7.0.5 (included in Patch 8).

                  Also the latest ePO 4.0 patch might help if not already installed.

                   

                  Then recheck the behaviour ...

                  • 6. Re: HIPS Events Lose Information after agent reinstall

                    We're already on ePO 4.0 Build 1333 (Patch 6).   I'm going to try HIPS patch 7.  We're not currently authorized to move to Patch 8 until completion of testing.  Although, the word I'm getting is that this is most likely on the ePO side.

                     

                    We found a couple of file servers that we'd been forced to reinstall the ma on earlier this year.  I did some queries on those to see if there was any system information missing from events prior to the install.  That group information remained associated with events after the ma reinstall.

                     

                    It looks like this is something recent, maybe a small update somewhere below the patch-level type.  So far I'm unable to determine just when this started.

                     

                    I don't see anything concerning ePO 4.5 that addresses this.  We're moving to it in the near future.

                    • 7. Re: HIPS Events Lose Information after agent reinstall
                      metalhead

                      Latest pacth for ePO 4.0 is patch 7.

                       

                      And don´t forget that I not meant an actual HIPS client software patch.

                      I meant the extension used inside ePO which is e.g. responsible for creating tables, registering events etc. There is an updated one available within the HIPS clients patch 8 package.

                      • 8. Re: HIPS Events Lose Information after agent reinstall

                        I'd forgotten that they released a new patch in Sept.  I'm going to run it on my test server this weekend to make sure nothings flaky then throw it on our production servers.  I've added the latest extensions for HIPS, but so far we're still seeing the same thing.  Our other problem of hosts not enforcing policies is actually helping me work on this issue.  Who'd a thunk it.