McAfee EPOCDE-AA-BA Product Guide - Page 216

Configuring Automatic Responses, Assigning permission sets to access Automatic Responses

Page 216 highlights

18 Responding to events in your network Configuring Automatic Responses Configuring Automatic Responses Use these tasks to configure the necessary resources to fully leverage Automatic Responses. Tasks • Assigning permission sets to access Automatic Responses on page 216 Use these tasks to assign the appropriate permission sets to access the Automatic Responses feature. • Working with SNMP servers on page 217 Use these tasks to configure Responses to use your SNMP server. You can configure Responses to send SNMP (Simple Network Management Protocol) traps to your SNMP server, which allows you to receive SNMP traps at the same location where you can use your network management application to view detailed information about the systems in your environment. • Working with registered executables and external commands on page 220 Use these tasks when working with registered executables and external commands. You can configure automatic response rules to run an external command when the rule is initiated. Assigning permission sets to access Automatic Responses Use these tasks to assign the appropriate permission sets to access the Automatic Responses feature. There are two permission sets specific to the Automatic Responses feature: • Automatic Responses • Event Notifications Users accessing this feature require additional permissions, depending on the specific component used. For example, to create an automatic response that triggers a predefined server task, users need full rights to the Server tasks permission sets. Additional permission sets that might be required include: • Client Events • Registered servers • Contacts • Rogue System Detection • Event Notifications • System Tree (view only) • Issue Management • System Tree access • Queries • Threat Event log Tasks • Assigning permissions to Notifications on page 216 Use this task to ensure that all desired administrators and users have the appropriate permissions to Notifications. The permissions to Notification enables McAfee ePO users to add registered executables. • Assigning permissions to Automatic Responses on page 217 Use this task to ensure that all desired administrators and users have the appropriate permissions to Responses. The permissions to Responses enables McAfee ePO users to create response rules for different event types and groups. Assigning permissions to Notifications Use this task to ensure that all desired administrators and users have the appropriate permissions to Notifications. The permissions to Notification enables McAfee ePO users to add registered executables. For option definitions click ? in the interface. 216 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Configuring Automatic Responses
Use these tasks to configure the necessary resources to fully leverage Automatic Responses.
Tasks
Assigning permission sets to access Automatic Responses
on page 216
Use these tasks to assign the appropriate permission sets to access the Automatic
Responses feature.
Working with SNMP servers
on page 217
Use these tasks to configure Responses to use your SNMP server. You can configure
Responses to send SNMP (Simple Network Management Protocol) traps to your SNMP
server, which allows you to receive SNMP traps at the same location where you can use
your network management application to view detailed information about the systems in
your environment.
Working with registered executables and external commands
on page 220
Use these tasks when working with registered executables and external commands. You
can configure automatic response rules to run an external command when the rule is
initiated.
Assigning permission sets to access Automatic Responses
Use these tasks to assign the appropriate permission sets to access the Automatic Responses feature.
There are two permission sets specific to the Automatic Responses feature:
Automatic Responses
Event Notifications
Users accessing this feature require additional permissions, depending on the specific component
used. For example, to create an automatic response that triggers a predefined server task, users need
full rights to the
Server tasks
permission sets. Additional permission sets that might be required include:
Client Events
Registered servers
Contacts
Rogue System Detection
Event Notifications
System Tree (view only)
Issue Management
System Tree access
Queries
Threat Event log
Tasks
Assigning permissions to Notifications
on page 216
Use this task to ensure that all desired administrators and users have the appropriate
permissions to Notifications. The permissions to Notification enables McAfee ePO users to
add registered executables.
Assigning permissions to Automatic Responses
on page 217
Use this task to ensure that all desired administrators and users have the appropriate
permissions to Responses. The permissions to Responses enables McAfee ePO users to
create response rules for different event types and groups.
Assigning permissions to Notifications
Use this task to ensure that all desired administrators and users have the appropriate permissions to
Notifications. The permissions to Notification enables McAfee ePO users to add registered executables.
For option definitions click
?
in the interface.
18
Responding to events in your network
Configuring Automatic Responses
216
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide