9 Replies Latest reply on Jun 25, 2012 7:18 AM by Tristan

    How do I setup a weekly email response in EPO 4.6 for most infected pc's.

      I want to setup an email notification once a week, with the 10 most infected pc's in our domain of that week.

       

      I'll have go to "Menu" -> "Automation" -> "Automatic Responses", but how do I setup the specific settings?

       

      Thank you.

        • 1. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.
          jking

          Good morning.  This task isn't anything that needs the web API to solve, you can accomplish this entirely within the ePO console.

           

          First, make sure you have your SMTP server configured -- ePO can't email you things without it.  Go to Configuration -> Server Settings -> Email Server to set it up.

           

          Next, create or find the query that you'd like to have mailed to you regularly.  For example, I see a "VSE: Top 10 Threat Sources" default query.  That might work for now, and then you might want to go back and edit the query to tweak the time range or other criteria to fine tune it after you get everything set up.

           

          After you know what query you want to run, go to Automation->Server Tasks and create a new task. 

           

          In the first step of the new task wizard, you just need to give the task a name and make sure it's enabled.

           

          The second step has most of the work.  What you're going to want to do first is run the query you found or created above -- so make the first task a 'Run Query' task, and choose the query you want to run.

           

          Next, you should see a 'Sub-action' menu ... choose 'email file' ... fill in the rest of the information about where to send it, and whether you want to see just the chart or additional drill down info.

           

          Hit next and add the schedule on the third step of the wizard.  Zip past the summary page, and once you've saved the server task you can choose to 'Run' it immediately to make sure you receive the email.  Check the server task log to verify that it worked.

           

          Once you've got the general setup down you might play around with creating different queries or, if you're running ePO 4.6 you can create reports with multiple queries in them (choose the action 'Run Report' instead of 'Run Query' to run a report in a server task).

           

          Hope this was useful to you,

           

          Jon

          1 of 1 people found this helpful
          • 2. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.

            I have the SMTP server configured.

             

            "VSE: Top 10 Threat Sources" would do, but I do not have that in my list of default under Server Tasks.

             

            See attached picture, ...

             

            Server_Tasks.jpg

             

            could I import this default, or are there screen shots available for this setup?

            • 3. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.
              Tristan

              Just create a new task to run the query and email it at the required schedule.

               

              Page 260 of the ePO 4.6 product guide has a step by step guide on how to set up a new server task to run a report.

               

              Instead of selecting a report choose a query and then set up a sub-action to email it. You could even build a custom query if you want.

              • 4. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.

                Great, that's very helpful. I already received a first email notification.

                 

                Now I recieve an email with a "weekly overview of top 10 most infected pc's this week"

                 

                When I click on a "Threat Target User Name" it shows me:

                 

                Event Category Threat Type Threat Target User Name Threat Target Host Name Detecting Product IPv4 Address Tags Detecting Product Name Detecting Product Version DAT Version Engine Version Last Communication


                What I would like to see to is the "exact name of the threat" (not just the "Treat Type") and when exactly (date and time) it occurred.

                 

                Do you know how I can alter the query to obtain this information?

                 

                Message was edited by: sbmoffshore on 6/20/12 10:29:56 AM CDT
                • 5. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.
                  Tristan

                  Edit the query. Under the columns section add the threat name field.

                   

                  If you don't want to mess with the default reports make a copy first and then do the customizations. Once your happy change your scheduled task to run your new report instead.

                   

                  threat_name.jpg

                  • 6. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.

                    Right, I now almost have all columns I want, except one.

                    The only item left on this list is that I would like to see when the exact malware was found.

                    (Now I only have "Last Communication" as a time-stamp).

                     

                    But I would like to see if the malware was caught on the same day or a different day, etc.

                    Is there a "Available Column" for that?

                     

                    Thanks!

                    • 7. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.
                      Tristan

                      'Event generated' is the column you probably want.

                       

                      This will be when the detection occurred on the client.

                      1 of 1 people found this helpful
                      • 8. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.

                        I now pretty much have what I want, except that now (see below image) the "Event Generated Time" starts with the 'oldest' time,

                        I want the most recent "Event Generated Time" on top (and than go down in anti-chronological oder). Is there any way I can change this?

                         

                        25-Jun-2012 13-55-59.png

                        • 9. Re: How do I setup a weekly email response in EPO 4.6 for most infected pc's.
                          Tristan

                          I think you can do it by changing the labels on the query. Even though this is in the 'Chart' section of the query i believe it impacts on the sort order of the report as well.

                           

                          sort by event.jpg

                          1 of 1 people found this helpful