McAfee HISCDE-AB-IA Product Guide - Page 12

Managing Your Protection, Information management, Host IPS dashboards

Page 12 highlights

Managing Your Protection Management of a Host Intrusion Prevention deployment includes monitoring, analyzing, and reacting to activities; changing and updating policies; and performing system tasks. Contents Information management Policy management System management Information management After you have installed Host Intrusion Prevention, you can track and report on security issues that arise in your environment. Use the dashboards for a daily view of the security situation or to run queries for detailed information on particular issues. Host IPS dashboards Dashboards are a collection of monitors that are an essential tool for managing your environment. Monitors can be anything from a chart-based query to a small web-application, like the MyAvert Threat Service. You can create and edit multiple dashboards if you have the permissions. Use any chart-based query as a dashboard that refreshes at a specified frequency, so you can put your most useful queries on a live dashboard. Host Intrusion Prevention provides two default dashboards with these monitors: Table 1: Host IPS dashboards and monitors Dashboard Monitors Host IPS • Firewall Status • Host IPS Status • Service Status • Count of IPS Client Rules • Content Versions • Top 10 NIPS Events by Source IP Host IPS Triggered Signatures • Desktop High Triggered Signatures • Desktop Medium Triggered Signatures • Desktop Low Triggered Signatures • Server High Triggered Signatures • Server Medium Triggered Signatures • Server Low Triggered Signatures 12 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Managing Your Protection
Management of a Host Intrusion Prevention deployment includes monitoring, analyzing, and
reacting to activities; changing and updating policies; and performing system tasks.
Contents
Information management
Policy management
System management
Information management
After you have installed Host Intrusion Prevention, you can track and report on security issues
that arise in your environment. Use the dashboards for a daily view of the security situation or
to run queries for detailed information on particular issues.
Host IPS dashboards
Dashboards are a collection of monitors that are an essential tool for managing your environment.
Monitors can be anything from a chart-based query to a small web-application, like the MyAvert
Threat Service. You can create and edit multiple dashboards if you have the permissions. Use
any chart-based query as a dashboard that refreshes at a specified frequency, so you can put
your most useful queries on a live dashboard.
Host Intrusion Prevention provides two default dashboards with these monitors:
Table 1: Host IPS dashboards and monitors
Monitors
Dashboard
Host IPS
Firewall Status
Host IPS Status
Service Status
Count of IPS Client Rules
Content Versions
Top 10 NIPS Events by Source IP
Host IPS Triggered Signatures
Desktop High Triggered Signatures
Desktop Medium Triggered Signatures
Desktop Low Triggered Signatures
Server High Triggered Signatures
Server Medium Triggered Signatures
Server Low Triggered Signatures
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
12