Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
499 Views 4 Replies Latest reply: Mar 31, 2014 12:28 PM by msitko RSS
gene33 Newcomer 35 posts since
Jun 15, 2012
Currently Being Moderated

Feb 6, 2014 10:20 AM

Run a script

I would really like to utilize the "run a script" functionality within the RTTA to populate information in our event tracker.  I can't seem to find any documentation on how this works though.  The built-in help doesn't say anything about what kind of script is expected, where the script is run, how variables are accessed, etc.

 

I tried a really simple hello world VBS script, but it gives an error message, I also tried a javascript hello world, to no avail either.

Attachments:
  • msitko Group Leader 19 posts since
    May 30, 2013
    Currently Being Moderated
    1. Feb 6, 2014 2:39 PM (in response to gene33)
    Re: Run a script

    I'm attempting to write a KB article on this, however I'm running into the same issue you are with it erroring every time, so I haven't been able to test much yet.

     

    It's my understanding that it works similar to the Windows command prompt.  You can call other programs, echo into text files, etc and use the variables provided to pass more information to the script.  I'll have more information when I can see what's causing the errors.

  • msitko Group Leader 19 posts since
    May 30, 2013
    Currently Being Moderated
    3. Feb 7, 2014 4:26 PM (in response to gene33)
    Re: Run a script

    It looks like you can call programs, such as batch files.  For example, I created this batch file in E:\temp\test.bat:

     

    echo %1 %2 > out.txt

     

    I then made this script in the RTTA:

     

    E:\temp\test.bat $ALERT_ID$ $ATTACK_ID$

     

    Running that script created an out.txt file on my desktop, containing the alert and attack ID for the alert I ran the script off of.

     

     

    The fact that print worked lead me to believe it was a scripting language as well, until I realized that print is a function in the command line, to print files.  At least with the ability to call a batch file (or other script, I assume) you can write whatever you want with whatever input you need.

  • msitko Group Leader 19 posts since
    May 30, 2013
    Currently Being Moderated
    4. Mar 31, 2014 12:28 PM (in response to msitko)
    Re: Run a script

    To circle back on this in case anyone else has this issue, it's been resolved in a hotfix, which will be available by contacting support

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points