McAfee HISCDE-AB-IA Product Guide - Page 15

Host IPS Event Info Hidden, Read, Firewall Outbound Learn Mode Status

Page 15 highlights

Managing Your Protection Information management • Blocked Attackers • Client Version • Content Version • Firewall Adaptive Mode Status • Firewall Fault (Errors) • Firewall Inbound Learn Mode Status • Firewall Outbound Learn Mode Status • Firewall Rule Count • Firewall Status • Host IPS Fault (Errors) • Host IPS Status • Install Directory • Language • Local Exception Rule Count • Network IPS Status • Pending Reboot • Plug-in Version • Product Status • Service Running • Hotfix/Patch Version • Product Version • Service Pack • Host IPS Event Info (Hidden, Read) • Signature Name Pre-defined queries In addition to custom queries, you can use several pre-defined queries as is, or edit them to obtain just the information you need. Select from these Host IPS predefined queries: HIP Query Summary Client Rules By Process Displays firewall client rules listed by process. Client Rules By Process/Port Displays firewall client rules listed by process and port range. Range Client Rules By Process/User Displays firewall client rules listed by process and user. Client Rules By Protocol/System Name Displays firewall client rules listed by protocol and system name. Client Rules By Protocol/Port Displays firewall client rules listed by protocol and port range. Range Client Rules by Protocol/Process Displays firewall client rules listed by protocol and process. Client Versions Displays top three client versions with a single category for all other versions. Clients Pending Restart Displays managed systems where Host IPS is deployed and the installer needs to restart the system. Content Versions Displays top three content versions with a single category for all other versions. Count of FW Client Rules Displays the number of Firewall client rules created over time. Count of IPS Client Rules Displays the number of IPS client rules created over time. Desktop High Triggered Signatures Displays the top 10 most triggered IPS signatures of High Severity (Critical). Desktop Medium Triggered Signatures Displays the top 10 most triggered IPS signatures of Medium Severity (Warning). Desktop Low Triggered Signatures Displays the top 10 most triggered IPS signatures of Low Severity (Notice). Events From Host IPS Trusted Displays events generated by systems within Host IPS trusted networks. Networks McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 15

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Blocked Attackers
Language
Local Exception Rule Count
Client Version
Content Version
Network IPS Status
Pending Reboot
Firewall Adaptive Mode Status
Firewall Fault (Errors)
Plug-in Version
Product Status
Firewall Inbound Learn Mode Status
Firewall Outbound Learn Mode Status
Service Running
Hotfix/Patch Version
Firewall Rule Count
Firewall Status
Product Version
Service Pack
Host IPS Fault (Errors)
Host IPS Status
Host IPS Event Info (Hidden, Read)
Signature Name
Install Directory
Pre-defined queries
In addition to custom queries, you can use several pre-defined queries as is, or edit them to
obtain just the information you need. Select from these Host IPS predefined queries:
Summary
HIP Query
Displays firewall client rules listed by process.
Client Rules By Process
Displays firewall client rules listed by process and port range.
Client Rules By Process/Port
Range
Displays firewall client rules listed by process and user.
Client Rules By Process/User
Displays firewall client rules listed by protocol and system name.
Client Rules By
Protocol/System Name
Displays firewall client rules listed by protocol and port range.
Client Rules By Protocol/Port
Range
Displays firewall client rules listed by protocol and process.
Client Rules by
Protocol/Process
Displays top three client versions with a single category for all other versions.
Client Versions
Displays managed systems where Host IPS is deployed and the installer needs to
restart the system.
Clients Pending Restart
Displays top three content versions with a single category for all other versions.
Content Versions
Displays the number of Firewall client rules created over time.
Count of FW Client Rules
Displays the number of IPS client rules created over time.
Count of IPS Client Rules
Displays the top 10 most triggered IPS signatures of High Severity (Critical).
Desktop High Triggered
Signatures
Displays the top 10 most triggered IPS signatures of Medium Severity (Warning).
Desktop Medium Triggered
Signatures
Displays the top 10 most triggered IPS signatures of Low Severity (Notice).
Desktop Low Triggered
Signatures
Displays events generated by systems within Host IPS trusted networks.
Events From Host IPS Trusted
Networks
Managing Your Protection
Information management
15
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5