McAfee HISCDE-AB-IA Product Guide - Page 144

Clientcontrol.exe utility

Page 144 highlights

Appendix B - Troubleshooting Clientcontrol.exe utility Name HipMgtPlugin.log Description McAfee Agent plug-in log FireTray.log/McTrayHip.log Tray log FireUI.log Client UI log Contains this data • Debug level logging • Policy enforcement timing statistics • Errors/warnings • Debug level logging • Errors/warnings • Debug level logging • Errors/warnings These log files grow until they reach the default maximum size of 100 MB. If larger or smaller log files are desired, the size can be controlled by adding the following registry value: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\HIP\MaxFwLogSize. To set the log size: 1 Select the HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\HIP registry key, right-click a blank space in the right pane, then select New, Dword Value. 2 Name the new value MaxFwLogSize. 3 Right-click MaxFwLogSize and select Modify. 4 Change the Value to the desired size of the logs. This value is entered in KB. 5 Click OK, then close the registry editor. NOTE: The MaxFwLogSize reg key controls the size of FireSvc.log, HipMgtPlugin.log, FireTray.logand FireUI.log. Creating and assigning a value to the above registry key sets the maximum size of all these log files. Clientcontrol.exe utility This command line utility helps automate upgrades and other maintenance tasks when third-party software is used to deploy Host Intrusion Prevention on client computers. It can be included in installation and maintenance scripts to temporarily disable IPS protection and activate logging functions. Function and Setup This utility allows administrators to perform the following on the McAfee Host IPS client: • Start the Host IPS service. • Stop the Host IPS service (requires administrator or time-based password). • Change log settings (requires administrator or time-based password). • Start/stop the Host IPS engines (requires administrator or time-based password). • Export the activity log to a formatted text file. • Display the NaiLite license data residing in the registry on the client computer. • Export configuration settings to a formatted text file. • Replace configuration settings with default policy settings. • Export IPS startup protection rules from the registry. 144 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Contains this data
Description
Name
McAfee Agent plug-in log
HipMgtPlugin.log
Debug level logging
Policy enforcement timing statistics
Errors/warnings
Tray log
FireTray.log/McTrayHip.log
Debug level logging
Errors/warnings
Client UI log
FireUI.log
Debug level logging
Errors/warnings
These log files grow until they reach the default maximum size of 100 MB. If larger or smaller
log files are desired, the size can be controlled by adding the following registry value:
HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\HIP\MaxFwLogSize
.
To set the log size:
1
Select the HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\HIP registry key, right-click a blank
space in the right pane, then select
New
,
Dword Value
.
2
Name the new value
MaxFwLogSize
.
3
Right-click
MaxFwLogSize
and select
Modify
.
4
Change the Value to the desired size of the logs. This value is entered in KB.
5
Click
OK
, then close the registry editor.
NOTE:
The
MaxFwLogSize
reg key controls the size of FireSvc.log, HipMgtPlugin.log,
FireTray.logand FireUI.log. Creating and assigning a value to the above registry key sets the
maximum size of all these log files.
Clientcontrol.exe utility
This command line utility helps automate upgrades and other maintenance tasks when third-party
software is used to deploy Host Intrusion Prevention on client computers. It can be included in
installation and maintenance scripts to temporarily disable IPS protection and activate logging
functions.
Function and Setup
This utility allows administrators to perform the following on the McAfee Host IPS client:
Start the Host IPS service.
Stop the Host IPS service (requires administrator or time-based password).
Change log settings (requires administrator or time-based password).
Start/stop the Host IPS engines (requires administrator or time-based password).
Export the activity log to a formatted text file.
Display the NaiLite license data residing in the registry on the client computer.
Export configuration settings to a formatted text file.
Replace configuration settings with default policy settings.
Export IPS startup protection rules from the registry.
Appendix B — Troubleshooting
Clientcontrol.exe utility
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
144