McAfee HISCDE-AB-IA Product Guide - Page 93

About the Activity Log tab, Customizing Activity Log options

Page 93 highlights

Working with Host Intrusion Prevention Clients Overview of the Windows client About the Activity Log tab Use the Activity Log tab to configure the logging feature and track Host Intrusion Prevention actions. The Activity Log contains a running log of activity. Most recent activity appears at the bottom of the list. Column Time Event What it shows The date and time of the Host Intrusion Prevention action. The feature that performed the action. • Traffic indicates a firewall action. • Application indicates an application blocking action. • Intrusion indicates an IPS action. • System indicates an event relating to the software's internal components. • Service indicates an event relating to the software's service or drivers. IP Address/User Intrusion Data The remote address that this communication was either sent to, or sent from. An icon indicating that Host Intrusion Prevention saved the packet data associated with this attack (appears only for IPS log entries). You can export the packet data associated with this log entry. Right-click the log entry to save the data to a Sniffer file. NOTE: This column appears only if you select Create Sniffer Capture... in the McAfee Options dialog box. Application Message Matched rule The program that caused the action. A description of the action, with as much detail as possible. The name of the rule that was matched. NOTE: This column is located on the far right of the screen, so you must scroll or resize the columns to view the column and its contents. Customizing Activity Log options Options at the top of the tab control logging settings delivered by the server-side Client UI policies after the client interface is unlocked. Task 1 In the Host IPS client console, click the Activity Log tab. 2 Select or deselect an option as needed. Select... Traffic Logging - Log All Blocked Traffic Logging - Log All Allowed Filter Options - Traffic To do this... Log all blocked firewall traffic. Log all allowed firewall traffic. Filter the data to display blocked and allowed firewall traffic. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 93

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

About the Activity Log tab
Use the Activity Log tab to configure the logging feature and track Host Intrusion Prevention
actions.
The Activity Log contains a running log of activity. Most recent activity appears at the bottom
of the list.
What it shows
Column
The date and time of the Host Intrusion Prevention action.
Time
The feature that performed the action.
Event
Traffic
indicates a firewall action.
Application
indicates an application blocking action.
Intrusion
indicates an IPS action.
System
indicates an event relating to the software's internal
components.
Service
indicates an event relating to the software's service or drivers.
The remote address that this communication was either sent to, or sent
from.
IP Address/User
An icon indicating that Host Intrusion Prevention saved the packet data
associated with this attack (appears only for IPS log entries). You can export
Intrusion Data
the packet data associated with this log entry. Right-click the log entry to
save the data to a Sniffer file.
NOTE:
This column appears only if you select
Create Sniffer Capture...
in the
McAfee Options
dialog box.
The program that caused the action.
Application
A description of the action, with as much detail as possible.
Message
The name of the rule that was matched.
NOTE:
This column is located on the far right of the screen, so you must
scroll or resize the columns to view the column and its contents.
Matched rule
Customizing Activity Log options
Options at the top of the tab control logging settings delivered by the server-side Client UI
policies after the client interface is unlocked.
Task
1
In the Host IPS client console, click the
Activity Log
tab.
2
Select or deselect an option as needed.
To do this...
Select...
Log all blocked firewall traffic.
Traffic Logging - Log All Blocked
Log all allowed firewall traffic.
Traffic Logging - Log All Allowed
Filter the data to display blocked and allowed firewall
traffic.
Filter Options - Traffic
Working with Host Intrusion Prevention Clients
Overview of the Windows client
93
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5