McAfee EPOCDE-AA-BA Product Guide - Page 215

Determining which events are forwarded immediately, Determining which events are forwarded

Page 215 highlights

Responding to events in your network Determining how events are forwarded 18 If you choose to send events immediately (as set by default), the agent forwards all events as soon as they are received. The default interval for processing event notifications is one minute. As a result, there might be a delay before events are processed. You can change the default interval in the Event Notifications server settings (Menu | Configuration | Server). If you choose not to have all events sent immediately, the agent forwards immediately only events that are designated by the issuing product as high priority. Other events are sent only at the agent-server communication. Tasks • Determining which events are forwarded immediately on page 215 Use this task to determine whether events are forwarded immediately or only at the agent-to-server communication interval. • Determining which events are forwarded on page 215 Use this task to determine which events are forwarded to the server. Determining which events are forwarded immediately Use this task to determine whether events are forwarded immediately or only at the agent-to-server communication interval. If the currently applied policy is not set for immediate uploading of events, either edit the currently applied policy or create a new McAfee Agent policy. This setting is configured on the Threat Event Log page. For option definitions click ? in the interface. Task 1 Click Menu | Policy | Policy Catalog, then select Product as McAfee Agent and Category as General. 2 Click on an existing agent policy. 3 On the Events tab, select Enable priority event forwarding. 4 Select the event severity. Events of the selected severity (and greater) are forwarded immediately to the server. 5 To regulate traffic, type an Interval between uploads (in minutes). 6 To regulate traffic size, type the Maximum number of events per upload. 7 Click Save. Determining which events are forwarded Use this task to determine which events are forwarded to the server. For option definitions click ? in the interface. Task 1 Click Menu | Configuration | Server Settings, select Event Filtering, then click Edit. 2 Select the desired events, then click Save. These settings take effect once all agents have called in. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 215

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

If you choose to send events immediately (as set by default), the agent forwards all events as soon as
they are received.
The default interval for processing event notifications is one minute. As a
result, there might be a delay before events are processed. You can
change the default interval in the Event Notifications server settings
(
Menu
|
Configuration
|
Server
).
If you choose not to have all events sent immediately, the agent forwards immediately only events
that are designated by the issuing product as high priority. Other events are sent only at the
agent-server communication.
Tasks
Determining which events are forwarded immediately
on page 215
Use this task to determine whether events are forwarded immediately or only at the
agent-to-server communication interval.
Determining which events are forwarded
on page 215
Use this task to determine which events are forwarded to the server.
Determining which events are forwarded immediately
Use this task to determine whether events are forwarded immediately or only at the agent-to-server
communication interval.
If the currently applied policy is not set for immediate uploading of events, either edit the currently
applied policy or create a new McAfee Agent policy. This setting is configured on the Threat Event Log
page.
For option definitions click
?
in the interface.
Task
1
Click
Menu
|
Policy
|
Policy Catalog
, then select
Product
as
McAfee Agent
and
Category
as
General
.
2
Click on an existing agent policy.
3
On the Events tab, select
Enable priority event forwarding
.
4
Select the event severity.
Events of the selected severity (and greater) are forwarded immediately to the server.
5
To regulate traffic, type an
Interval between uploads
(in minutes).
6
To regulate traffic size, type the
Maximum number of events per upload
.
7
Click
Save
.
Determining which events are forwarded
Use this task to determine which events are forwarded to the server.
For option definitions click
?
in the interface.
Task
1
Click
Menu
|
Configuration
|
Server Settings
, select
Event Filtering
, then click
Edit
.
2
Select the desired events, then click
Save
.
These settings take effect once all agents have called in.
Responding to events in your network
Determining how events are forwarded
18
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
215