McAfee EPOCDE-AA-BA Product Guide - Page 33

Choosing an ePO Notification Event interval, Configuring settings for global updates

Page 33 highlights

Configuring general server settings Configuring general server settings 4 Choosing an ePO Notification Event interval This setting determines how often ePO Notification Events are sent to the Automatic Response system. There are three types of ePO Notification Events: • Client events - Events that occur on managed systems. For example, "Product update succeeded." • Threat events - Events that indicate a possible threat is detected. For example, "Virus detected." • Server events - Events that occur on the server. For example, "Repository pull failed." An automatic response can be triggered only after the Automatic Response system receives a notification. McAfee recommends that you specify a relatively short interval for sending these Notification events. McAfee recommends that you choose an evaluation interval that is frequent enough to ensure that the Automatic Response system can respond to an event in a timely manner, but infrequent enough to avoid excessive bandwidth consumption. Task For option definitions, click ? in the interface. 1 Click Menu | Configuration | Server Settings, select Event Notifications from the Setting Categories, then click Edit. 2 Specify a value between 1 and 9,999 minutes for the Evaluation Interval (1 minute by default), then click Save. Configuring settings for global updates Global updates automate repository replication in your network. The content distributed to repositories during a global update, and whether global updates are enabled are configured using the Global Updating server setting. Global updates are disabled by default. However, McAfee recommends that you enable and use them as part of your updating strategy. You can specify a randomization interval and package types to be distributed during the update. The randomization interval specifies the time period in which all systems are updated. Systems are updated randomly within the specified interval. Task For option definitions, click ? in the interface. 1 Click Menu | Configuration | Server Settings, select Global Updating from the Setting Categories, then click Edit. 2 Set the status to Enabled and specify a Randomization interval between 0 and 32,767 minutes. 3 Specify which Package types to include in the global updates: • All packages - Select this option to include all signatures and engines, and all patches and service packs. • Selected packages - Select this option to limit the signatures and engines, and patches and service packs included in the global update. When using global updating, McAfee recommends scheduling a regular pull task (to update the master repository) at a time when network traffic is minimal. Although global updating is much faster than other methods, it increases network traffic during the update. For more information about performing global updates, see Global updating under Product and update deployment. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 33

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Choosing an ePO Notification Event interval
This setting determines how often
ePO Notification Events
are sent to the Automatic Response system.
There are three types of
ePO Notification Events
:
Client events — Events that occur on managed systems. For example, "Product update succeeded."
Threat events — Events that indicate a possible threat is detected. For example, "Virus detected."
Server events — Events that occur on the server. For example, "Repository pull failed."
An automatic response can be triggered only after the Automatic Response system receives a
notification. McAfee recommends that you specify a relatively short interval for sending these
Notification events. McAfee recommends that you choose an evaluation interval that is frequent
enough to ensure that the Automatic Response system can respond to an event in a timely manner,
but infrequent enough to avoid excessive bandwidth consumption.
Task
For option definitions, click
?
in the interface.
1
Click
Menu
|
Configuration
|
Server Settings
, select
Event Notifications
from the
Setting Categories
, then click
Edit
.
2
Specify a value between 1 and 9,999 minutes for the
Evaluation Interval
(1 minute by default), then
click
Save
.
Configuring settings for global updates
Global updates automate repository replication in your network. The content distributed to repositories
during a global update, and whether global updates are enabled are configured using the Global
Updating server setting.
Global updates are disabled by default. However, McAfee recommends that you enable and use them
as part of your updating strategy. You can specify a randomization interval and package types to be
distributed during the update. The randomization interval specifies the time period in which all
systems are updated. Systems are updated randomly within the specified interval.
Task
For option definitions, click
?
in the interface.
1
Click
Menu
|
Configuration
|
Server Settings
, select
Global Updating
from the
Setting Categories
, then click
Edit
.
2
Set the status to
Enabled
and specify a
Randomization interval
between 0 and 32,767 minutes.
3
Specify which
Package types
to include in the global updates:
All packages
— Select this option to include all signatures and engines, and all patches and service
packs.
Selected packages
— Select this option to limit the signatures and engines, and patches and service
packs included in the global update.
When using global updating, McAfee recommends scheduling a regular
pull task (to update the master repository) at a time when network
traffic is minimal. Although global updating is much faster than other
methods, it increases network traffic during the update. For more
information about performing global updates, see
Global updating
under
Product and update deployment
.
Configuring general server settings
Configuring general server settings
4
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
33