McAfee HISCDE-AB-IA Product Guide - Page 14

Common Host IPS properties

Page 14 highlights

Managing Your Protection Information management Query Parameters have no allow/block action. IPS Catalog rules and • groups have the leafNodeId filter value set to 0, • so to view firewall client rules only, set the leafNodeId filter value to > 0. • • Leaf Node ID Local Services Log Status IP Protocol • Match Intrusion • Media Type • Name • Note • Remote Services • Rule ID • Schedule End • Schedule Start • Switch When Expired • Transport Protocol Host IPS 8.0 Firewall Client Rule Executables • Fingerprint • Name • Note • Path • Rule ID • Signer Name Host IPS 8.0 IPS Client Rules • Creation Date • Description • Executable Name • Executable Path • Fingerprint • Full Executable Name • Include All Executables • Include All Signatures • Include All Users • Last Modified Date • Local Version • Reaction • Signature ID • Signer Name • Status • User Name Host IPS 8.0 IPS Exceptions • IPS Exception Rule • IPS Rules Policy Common Host IPS properties The Host IPS custom queries and some of the other custom queries allow you to include these Host IPS properties: • Agent type • IPS Adaptive Mode Status 14 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Parameters
Query
have no allow/block action. IPS Catalog rules and
groups have the
leafNodeId
filter value set to
0
,
Leaf Node ID
Local Services
so to view firewall client rules only, set the
leafNodeId filter value to
>0
.
Log Status
IP Protocol
Match Intrusion
Media Type
Name
Note
Remote Services
Rule ID
Schedule End
Schedule Start
Switch When Expired
Transport Protocol
Host IPS 8.0 Firewall Client Rule Executables
Fingerprint
Name
Note
Path
Rule ID
Signer Name
Host IPS 8.0 IPS Client Rules
Creation Date
Description
Executable Name
Executable Path
Fingerprint
Full Executable Name
Include All Executables
Include All Signatures
Include All Users
Last Modified Date
Local Version
Reaction
Signature ID
Signer Name
Status
User Name
Host IPS 8.0 IPS Exceptions
IPS Exception Rule
IPS Rules Policy
Common Host IPS properties
The Host IPS custom queries and some of the other custom queries allow you to include these
Host IPS properties:
IPS Adaptive Mode Status
Agent type
Managing Your Protection
Information management
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
14