McAfee HISCDE-AB-IA Product Guide - Page 13

Host IPS queries, Predefined and custom queries to analyze your protection

Page 13 highlights

Managing Your Protection Information management For more information about creating and using dashboards, see the ePolicy Orchestrator documentation. Host IPS queries Host Intrusion Prevention includes query functionality through ePolicy Orchestrator. You can create useful queries from events and properties stored in the ePO database or use predefined queries. You can produce queries for a group of selected client systems, or limit report results by product or system criteria. You can export reports into a variety of file formats, including HTML and Microsoft Excel. Query options: • Setting a filter to gather only selected information. Choose which group or tags to include in the report. • Setting a data filter using logical operators, to define precise filters on the data returned by the report. • Generating graphical reports from the information in the database, filtering the reports as needed, printing the reports, and exporting them to other software. • Running queries of computers, events, and installations. Predefined and custom queries to analyze your protection The reporting feature contains predefined queries from Host Intrusion Prevention and allows you to create custom queries. Organize and maintain custom queries to suit your needs. For example, if you customize settings for a report, export these settings as a template. After creating custom templates, organize them in logical groupings so that you can run them as needed on a daily, weekly, or monthly basis. After a report is generated, you view summary information, as determined by the filter, if any, that you have set. From the summary information you drill down to one or two levels for detailed information, all in the same report. You control how much report information is visible to different users; for example, global administrators versus other users. Some users view reports only on systems in sites where they have permissions. Report information is also controlled by applying filters. Custom queries You can create four specific Host IPS queries with the Query Builder under Others: Host IPS 8.0 Firewall Client Rules, Host IPS 8.0 Firewall Client Rule Executables, Host IPS 8.0 IPS Client Rules, and Host IPS 8.0 IPS Exceptions. Parameters for these queries include: Table 2: Host IPS queries and parameters Query Parameters Host IPS 8.0 Catalog Firewall Rules and Firewall • Client Rules • NOTE: This query returns IPS Catalog firewall • rules, IPS Catalog firewall groups, and firewall client rules. Possible action values are allow, block, • and jump, with jump the action for groups, which • Action Direction Enabled Last Modified Last Modifying User McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 13

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

For more information about creating and using dashboards, see the ePolicy Orchestrator
documentation.
Host IPS queries
Host Intrusion Prevention includes query functionality through ePolicy Orchestrator. You can
create useful queries from events and properties stored in the ePO database or use predefined
queries.
You can produce queries for a group of selected client systems, or limit report results by product
or system criteria. You can export reports into a variety of file formats, including HTML and
Microsoft Excel.
Query options:
Setting a filter to gather only selected information. Choose which group or tags to include
in the report.
Setting a data filter using logical operators, to define precise filters on the data returned by
the report.
Generating graphical reports from the information in the database, filtering the reports as
needed, printing the reports, and exporting them to other software.
Running queries of computers, events, and installations.
Predefined and custom queries to analyze your protection
The reporting feature contains predefined queries from Host Intrusion Prevention and allows
you to create custom queries.
Organize and maintain custom queries to suit your needs. For example, if you customize settings
for a report, export these settings as a template. After creating custom templates, organize
them in logical groupings so that you can run them as needed on a daily, weekly, or monthly
basis.
After a report is generated, you view summary information, as determined by the filter, if any,
that you have set. From the summary information you drill down to one or two levels for detailed
information, all in the same report.
You control how much report information is visible to different users; for example, global
administrators versus other users. Some users view reports only on systems in sites where they
have permissions. Report information is also controlled by applying filters.
Custom queries
You can create four specific Host IPS queries with the Query Builder under
Others
: Host IPS
8.0 Firewall Client Rules, Host IPS 8.0 Firewall Client Rule Executables, Host IPS 8.0 IPS Client
Rules, and Host IPS 8.0 IPS Exceptions.
Parameters for these queries include:
Table 2: Host IPS queries and parameters
Parameters
Query
Host IPS 8.0 Catalog Firewall Rules and Firewall
Client Rules
NOTE:
This query returns IPS Catalog firewall
rules, IPS Catalog firewall groups, and firewall
Action
Direction
Enabled
Last Modified
client rules. Possible action values are
allow
,
block
,
and
jump
, with jump the action for groups, which
Last Modifying User
Managing Your Protection
Information management
13
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5