Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
377 Views 4 Replies Latest reply: Jan 21, 2014 6:10 AM by rpd85 RSS
rpd85 Newcomer 27 posts since
Feb 14, 2013
Currently Being Moderated

Jan 14, 2014 9:53 AM

DLP 9.3 – How to query all details of Agent Override events

With Host DLP 9.3, there is a “DLP Operational Events” menu item in ePO. I have created a filter to display all events where an administrator has generated an agent override key. Clicking on any one of these events shows the “DLP Incident Information” – in this case, the fields include the “duration” of the override and “business reason” for granting it.

 

What I am trying to do now if figure out a way to run a query or report that can be emailed to a manager that will show how many override keys were generated during a specified period of time (such as within the last week), and all the relevant details of each override – duration, business reason, requesting user name, name of the administrator who granted the override, etc.

 

So far, I have created a query using the “DLP Events” Result Type with the filter “Event Type Equals Administrative: Agent Override Key Generated”; but I can’t find anything in the available properties or columns that will display the incident details for each override event.

 

Does anyone know if there is a way to export this kind of info, or can it only be seen by logging into ePO? Our ePO version is 4.6.6.

 

Thanks in advance!

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points