McAfee EPOCDE-AA-BA Product Guide - Page 211

Responding to events in your network

Page 211 highlights

18 Responding to events in your network Using the ePolicy Orchestrator Automatic response feature, you can configure your server to automatically trigger an action in response to various types of events; including threat, client, and server events. Are you creating an Automatic Response rule for the first time? When creating a new automatic response rule for the first time: 1 Understand Automatic Responses and how it works with the System Tree and your network. 2 Plan your implementation. Which users need to know about which events? 3 Prepare the components and permissions used with Automatic Responses, including: • Automatic Responses permissions - Create or edit permission sets and ensure that they are assigned to the appropriate McAfee ePO users. • Email server - Configure the email (SMTP) server at Server Settings. • Email contacts list - Specify the list from which you select recipients of notification messages at Contacts. • Registered executables - Specify a list of registered executables to run when the conditions of a rule are met. • Rogue System Detection permission - Create or edit permission sets and ensure that they are assigned to the appropriate McAfee ePO users. • Server tasks - Create server tasks for use as actions to be carried out as a result of a response rule. • SNMP servers - Specify a list of SNMP servers to use while creating rules. You can configure rules to send SNMP traps to SNMP servers when the conditions are met to initiate a notification message. Contents About using Automatic Responses Automatic Responses and how it works Planning Determining how events are forwarded Configuring Automatic Responses Creating and editing Automatic Response rules Frequently asked questions McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 211

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

18
Responding to events in your network
Using the ePolicy Orchestrator Automatic response feature, you can configure your server to
automatically trigger an action in response to various types of events; including threat, client, and
server events.
Are you creating an Automatic Response rule for the first time?
When creating a new automatic response rule for the first time:
1
Understand Automatic Responses and how it works with the System Tree and your network.
2
Plan your implementation. Which users need to know about which events?
3
Prepare the components and permissions used with Automatic Responses, including:
Automatic Responses permissions — Create or edit permission sets and ensure that they are
assigned to the appropriate McAfee ePO users.
Email server — Configure the email (SMTP) server at
Server Settings
.
Email contacts list — Specify the list from which you select recipients of notification messages at
Contacts
.
Registered executables — Specify a list of registered executables to run when the conditions of
a rule are met.
Rogue System Detection permission — Create or edit permission sets and ensure that they are
assigned to the appropriate McAfee ePO users.
Server tasks — Create server tasks for use as actions to be carried out as a result of a response
rule.
SNMP servers — Specify a list of SNMP servers to use while creating rules. You can configure
rules to send SNMP traps to SNMP servers when the conditions are met to initiate a notification
message.
Contents
About using Automatic Responses
Automatic Responses and how it works
Planning
Determining how events are forwarded
Configuring Automatic Responses
Creating and editing Automatic Response rules
Frequently asked questions
18
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
211