McAfee AVDCDE-BA-CA User Guide - Page 282

VirusScan software as an Alert Manager client, Configuring the Alert Manager client utility

Page 282 highlights

Using VirusScan Utilities VirusScan software as an Alert Manager client VirusScan software works as a client program with respect to NetShield software and an Alert Manager server. It can send alert "events" whenever it detects a virus or malicious software to any Alert Manager server you specify. The Alert Manager server then relays those events-and any others it receives from other workstations-as alert messages, via the methods you or your system administrator defined for alert distribution. VirusScan software can instead send these same alert messages as text (.ALR) files to a Centralized Alerting directory visible to the Alert Manager server. The Alert Manager server checks the Centralized Alerting directory periodically, looking for any new .ALR files, and distributing the alert messages from any it finds. Š NOTE: McAfee recommends that you send alert events directly to an Alert Manager server rather than via Centralized Alerting, unless your network configuration does not permit you to use Alert Manager servers. The Alert Manager server can work in conjunction with Network Associates Event Orchestrator software to tie alert messages into the Network Associates Magic HelpDesk application for trouble-ticket generation and other features. Alert Manager messages also contain much richer data than do those sent via Centralized Alerting. Enabling SNMP traps for Alert Manager will collect a host of information about the computer that generates the alert message and its software configuration. The VirusScan client can supplement either method with Desktop Management Interface (DMI) alerts for network management software, such as Hewlett-Packard OpenView, to process. Configuring the Alert Manager client utility VirusScan software includes a simple client configuration utility that allows you to choose the Alert Manager server that you want to receive alert events, designate a Centralized Alerting directory to receive alert messages, and specify the numeric value of DMI alert messages you want to send. Setting up a complete alert system is a two-part process: First, you must enable the Alert Manager Client Configuration utility and point it to the correct Alert Manager server or Centralized Alerting location. Next, you must verify that you have selected the Notify Alert Manager checkbox in the VirusScan Advanced Alert property page, in the Alert page for the E-Mail Scan extension and in the Alert pages for each VShield module you have enabled. 282 McAfee VirusScan Anti-Virus Software

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344

Using VirusScan Utilities
282
McAfee VirusScan Anti-Virus Software
VirusScan software as an Alert Manager client
VirusScan software works as a client program with respect to NetShield
software and an Alert Manager server. It can send alert
events
whenever it
detects a virus or malicious software to any Alert Manager server you specify.
The Alert Manager server then relays those events
and any others it receives
from other workstations
as alert messages, via the methods you or your
system administrator defined for alert distribution.
VirusScan software can instead send these same alert messages as text (.ALR)
files to a Centralized Alerting directory visible to the Alert Manager server.
The Alert Manager server checks the Centralized Alerting directory
periodically, looking for any new .ALR files, and distributing the alert
messages from any it finds.
NOTE:
McAfee recommends that you send alert events directly to an
Alert Manager server rather than via Centralized Alerting, unless your
network configuration does not permit you to use Alert Manager servers.
The Alert Manager server can work in conjunction with Network
Associates Event Orchestrator software to tie alert messages into the
Network Associates Magic HelpDesk application for trouble-ticket
generation and other features.
Alert Manager messages also contain much richer data than do those sent
via Centralized Alerting. Enabling SNMP traps for Alert Manager will
collect a host of information about the computer that generates the alert
message and its software configuration.
The VirusScan client can supplement either method with Desktop
Management Interface (DMI) alerts for network management software, such
as Hewlett-Packard OpenView, to process.
Configuring the Alert Manager client utility
VirusScan software includes a simple client configuration utility that allows
you to choose the Alert Manager server that you want to receive alert events,
designate a Centralized Alerting directory to receive alert messages, and
specify the numeric value of DMI alert messages you want to send.
Setting up a complete alert system is a two-part process: First, you must enable
the Alert Manager Client Configuration utility and point it to the correct Alert
Manager server or Centralized Alerting location. Next, you must verify that
you have selected the
Notify Alert Manager
checkbox in the VirusScan
Advanced Alert property page, in the Alert page for the E-Mail Scan extension
and in the Alert pages for each VShield module you have enabled.