McAfee HISCDE-AB-IA Product Guide - Page 25

Host IPS server tasks, Menu | Automation | Server Tasks, New Task

Page 25 highlights

Managing Your Protection System management 5 Assign other permission sets as required: For this Host IPS feature Host IPS events Host IPS client IPS rules Host IPS client firewall rules Host IPS dashboards Host IPS queries Assign this permission set Host Intrusion Prevention - IPS, Event log, Systems, System Tree access Host Intrusion Prevention - IPS, Event log, Systems, System Tree access Host Intrusion Prevention - Firewall, Event log, Systems, System Tree access Dashboard, Queries Queries Host IPS server tasks Host Intrusion Prevention provides several preconfigured and configurable server tasks that you can set to run on a specified schedule or immediately as part of Host Intrusion Prevention protection maintenance. You can create custom Host Intrusion Prevention server tasks by clicking New Task and selecting one or more Host IPS properties on the Actions tab of the Server Task Builder. For more information on using and creating server tasks, see the ePolicy Orchestrator documentation. To work with an existing server task, click Menu | Automation | Server Tasks, then click the appropriate command under Actions. To create a custom server task, click New Task and follow the steps in the Server Task Builder wizard. Table 4: Preconfigured and custom server tasks Server Task Description Host IPS Property Translator (Preconfigured) This server task translates Host Intrusion Prevention client rules that are stored in the ePolicy Orchestrator database to handle Host Intrusion Prevention sorting, grouping, and filtering of data. This task runs automatically every 15 minutes and requires no user interaction. You can, however, run it manually if you need to see immediate feedback from actions on the client. Repository Pull (Custom) This server task allows you to create a custom task to retrieve packages from the source site and place them in the master repository. Select the Host IPS Content as a package type to retrieve content updates automatically. Run Query (Custom) This server task allows you to create a custom task to run Host Intrusion Prevention preconfigured queries at a specified time and schedule. Purge Threat Event Log (Custom) This server task allows you to create a custom task to purge threat event logs based on a Host Intrusion Prevention query. Select a Host IPS Events query to purge from the log. Export Policies (Custom) This server task allows you to download an xml file that contains the associated Host Intrusion Prevention policy. Export Queries (Custom) This server task allows you to create a Host Intrusion Prevention query output file that can be saved or emailed. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 25

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

5
Assign other permission sets as required:
Assign this permission set
For this Host IPS feature
Host Intrusion Prevention — IPS, Event log, Systems,
System Tree access
Host IPS events
Host Intrusion Prevention — IPS, Event log, Systems,
System Tree access
Host IPS client IPS rules
Host Intrusion Prevention — Firewall, Event log,
Systems, System Tree access
Host IPS client firewall rules
Dashboard, Queries
Host IPS dashboards
Queries
Host IPS queries
Host IPS server tasks
Host Intrusion Prevention provides several preconfigured and configurable server tasks that
you can set to run on a specified schedule or immediately as part of Host Intrusion Prevention
protection maintenance. You can create custom Host Intrusion Prevention server tasks by
clicking New Task and selecting one or more Host IPS properties on the Actions tab of the
Server Task Builder. For more information on using and creating server tasks, see the ePolicy
Orchestrator documentation.
To work with an existing server task, click
Menu | Automation | Server Tasks
, then click
the appropriate command under Actions. To create a custom server task, click
New Task
and
follow the steps in the Server Task Builder wizard.
Table 4: Preconfigured and custom server tasks
Description
Server Task
This server task translates Host Intrusion Prevention client
rules that are stored in the ePolicy Orchestrator database
Host IPS Property Translator (Preconfigured)
to handle Host Intrusion Prevention sorting, grouping, and
filtering of data. This task runs automatically every 15
minutes and requires no user interaction. You can,
however, run it manually if you need to see immediate
feedback from actions on the client.
This server task allows you to create a custom task to
retrieve packages from the source site and place them in
Repository Pull (Custom)
the master repository. Select the Host IPS Content as a
package type to retrieve content updates automatically.
This server task allows you to create a custom task to run
Host Intrusion Prevention preconfigured queries at a
specified time and schedule.
Run Query (Custom)
This server task allows you to create a custom task to
purge threat event logs based on a Host Intrusion
Purge Threat Event Log (Custom)
Prevention query. Select a Host IPS Events query to purge
from the log.
This server task allows you to download an xml file that
contains the associated Host Intrusion Prevention policy.
Export Policies (Custom)
This server task allows you to create a Host Intrusion
Prevention query output file that can be saved or emailed.
Export Queries (Custom)
Managing Your Protection
System management
25
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5