McAfee HISCDE-AB-IA Product Guide - Page 85

Setting options for IPS logging, Disabling Host IPS engines, Help | Troubleshooting, Disabled

Page 85 highlights

Working with Host Intrusion Prevention Clients Overview of the Windows client Setting options for IPS logging As part of troubleshooting you can create IPS activity logs that can be analyzed on the system or sent to McAfee support to help resolve problems. Use this task to enable IPS logging. Task 1 In the Host IPS console, select Help | Troubleshooting. 2 Select the IPS message type: • Debug • Disabled • Error • Information • Warning If the message type is set to Disabled, no message is logged. 3 Click OK. The information is written to HipShield.log at C:\Documents and Settings\All Users\Application Data\McAfee\Host Intrusion Prevention; on Windows Vista and late at C:\Program Data\McAfee\Host Intrusion Prevention\. Settings options for Firewall logging As part of troubleshooting you can create firewall activity logs that can be analyzed on the system or sent to McAfee support to help resolve problems. Use this task to enable Firewall logging. Task 1 In the Host IPS console, select Help | Troubleshooting. 2 Select the Firewall message type: • Debug • Disabled • Error • Information • Warning If the message type is set to Disabled, no message is logged. 3 Click OK. The information is written to FireSvc.log at C:\Documents and Settings\All Users\Application Data\McAfee\Host Intrusion Prevention\; on Windows Vista and later at C:\Program Data\McAfee\Host Intrusion Prevention\. After the file reaches 100 MB, a new file is created. Disabling Host IPS engines As part of troubleshooting, you can also disable class engines that protect a client. McAfee recommends that only administrators communicating with McAfee support use this troubleshooting procedure. For a better understanding of what each class protects, see the section onWriting Custom Signatures. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 85

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Setting options for IPS logging
As part of troubleshooting you can create IPS activity logs that can be analyzed on the system
or sent to McAfee support to help resolve problems. Use this task to enable IPS logging.
Task
1
In the Host IPS console, select
Help | Troubleshooting
.
2
Select the IPS message type:
Debug
Disabled
Error
Information
Warning
If the message type is set to
Disabled
, no message is logged.
3
Click
OK
. The information is written to HipShield.log at C:\Documents and Settings\All
Users\Application Data\McAfee\Host Intrusion Prevention; on Windows Vista and late at
C:\Program Data\McAfee\Host Intrusion Prevention\.
Settings options for Firewall logging
As part of troubleshooting you can create firewall activity logs that can be analyzed on the
system or sent to McAfee support to help resolve problems. Use this task to enable Firewall
logging.
Task
1
In the Host IPS console, select
Help | Troubleshooting
.
2
Select the Firewall message type:
Debug
Disabled
Error
Information
Warning
If the message type is set to
Disabled
, no message is logged.
3
Click
OK
. The information is written to FireSvc.log at C:\Documents and Settings\All
Users\Application Data\McAfee\Host Intrusion Prevention\; on Windows Vista and later at
C:\Program Data\McAfee\Host Intrusion Prevention\. After the file reaches 100 MB, a new
file is created.
Disabling Host IPS engines
As part of troubleshooting, you can also disable class engines that protect a client. McAfee
recommends that only administrators communicating with McAfee support use this
troubleshooting procedure. For a better understanding of what each class protects, see the
section on
Writing Custom Signatures
.
Working with Host Intrusion Prevention Clients
Overview of the Windows client
85
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5