McAfee EPOCDE-AA-BA Product Guide - Page 223

Setting filters for the rule, Setting thresholds of the rule, Automation, Automatic Responses, Actions

Page 223 highlights

Responding to events in your network Creating and editing Automatic Response rules 18 Task 1 Click Menu | Automation | Automatic Responses, then click Actions | New Response, or Edit next to an existing rule. The Response Builder wizard opens. Figure 18-1 Notifications Rules page 2 On the Description page, type a unique name and any notes for the rule. Rule names on each server must be unique. For example, if one user creates a rule named Emergency Alert, no other user (including global administrators) can create a rule with that name. 3 From the Language menu, select the language the rule uses. 4 Select the Event group and Event type that trigger this response. 5 Select whether the rule is Enabled or Disabled next to Status. 6 Click Next. Setting filters for the rule Use this task to set the filters for the response rule on the Filters page of the Response Builder wizard. For option definitions click ? in the interface. Task 1 From the Available Properties list, select the desired property and specify the value to filter the response result. Available Properties depend on the event type and event group selected on the Description page of the wizard. 2 Click Next. Setting thresholds of the rule Use this task to define when the event triggers the rule on the Aggregation page of the Response Builder wizard. A rule's thresholds are a combination of aggregation, throttling, and grouping. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 223

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Task
1
Click
Menu
|
Automation
|
Automatic Responses
, then click
Actions
|
New Response
, or
Edit
next to an existing
rule.
The Response Builder wizard opens.
Figure 18-1
Notifications Rules page
2
On the Description page, type a unique name and any notes for the rule.
Rule names on each server must be unique. For example, if one user
creates a rule named Emergency Alert, no other user (including global
administrators) can create a rule with that name.
3
From the Language menu, select the language the rule uses.
4
Select the
Event group
and
Event type
that trigger this response.
5
Select whether the rule is
Enabled
or
Disabled
next to Status.
6
Click
Next
.
Setting filters for the rule
Use this task to set the filters for the response rule on the Filters page of the Response Builder wizard.
For option definitions click
?
in the interface.
Task
1
From the Available Properties list, select the desired property and specify the value to filter the
response result.
Available Properties depend on the event type and event group selected
on the Description page of the wizard.
2
Click
Next
.
Setting thresholds of the rule
Use this task to define when the event triggers the rule on the Aggregation page of the Response
Builder wizard.
A rule’s thresholds are a combination of aggregation, throttling, and grouping.
Responding to events in your network
Creating and editing Automatic Response rules
18
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
223