5 Replies Latest reply on Sep 25, 2012 3:58 PM by whh

    Automatic Responses Not Triggering

    awsomaha

      I have a AR setup to send an email whenever their is a block and the os type is server.  This was setup so we can see if something on the Servers was getting blocked we didn't want to.  This has worked fine up until about 2 weeks ago, then it just stopped.  I have verfied the smtp server is setup correctly by sending a test email to myself (which I received).  So for troubleshooting purpose, I changed it to just blocked, and no OS type and still nothing.  I was wondering were else can I look for errors to see what is stopping this.

        • 1. Re: Automatic Responses Not Triggering
          rackroyd

          Logging in this area is thin on the ground unfortunately, but the three logs to consider are: epoapsvr.log, server.log and orion.log. Specifically orion.log when debug logging is enabled for that file.

          The notifications are set to sweep every 60 seconds for new triggers I believe. Debug orion logging is otherwise very noisy though.

           

          See: KB52369 - How to enable debug logging to capture details in the Orion.log to troubleshoot console log on issues

           

          You should at least be seeing the rules sweep every minute, and when your rule is triggered it shoud be recorded too.

           

          Rgds,

           

          Rob.

          1 of 1 people found this helpful
          • 2. Re: Automatic Responses Not Triggering
            metalhead

            And the first thing would be that the events are appearing in ePO e.g. Threat event protocol or reporting.

             

            Regards Tom

            • 3. Re: Automatic Responses Not Triggering
              Attila Polinger

              Hi,

               

              in addition you could check directly in the database if the events that earlier triggered this AR has or has not stopped coming.

              Also, some apply IP restrictions on internal SMTP servers to stop abuse, maybe it is worth checking if the ePO server IP is on the allowed list for the SMTP server and noone did a trick with you, etc.

               

              Attila

              • 4. Re: Automatic Responses Not Triggering
                greatscott

                restart the ePO services. we had an AR setup for viruses in a certain container, the AR stopped working out of nowhere and mcafee support told us to restart the mcafee services (all 3 of them). started working thereafter.

                • 5. Re: Automatic Responses Not Triggering
                  whh

                  Checking the orion logs is a good idea.  For my issue, I've found instances of

                   

                  Error processing notification. Operation aborted.

                   

                  and

                   

                  Reference to unknown table:epoThreatEvent

                   

                   

                  Looks like something is whacky with the schema.

                   

                  Has anyone seen this?   What was the solution?