Default Rules; Planning - McAfee EPOLICY ORCHESTRATOR 4.0.2 Product Manual

Table of Contents

Advertisement

Sending Notifications

Planning

Default rules

ePolicy Orchestrator provides six default rules that you can enable for immediate use while you
learn more about the feature.
NOTE:
Once enabled, the default rules send notification messages to the email address you
provided in the ePO installation wizard.
Before enabling any of the default rules:
• Specify the email server (at Configuration | Server Settings) from which the notification
messages are sent.
• Ensure the recipient email address is the one you want to receive email messages. This
address is configured on the Notifications page of the wizard.
Default notification rules
Rule Name
Daily unknown product
notification
Daily unknown category
notification
Virus detected and not
removed
Virus detected heuristics and
not removed
Repository update or
replication failed
Non-compliant computer
detected
Planning
Before creating rules that send notifications, save time by planning:
McAfee ePolicy Orchestrator 4.0.2 Product Guide
Associated Events
Any events from any unknown
products.
Any event of an unknown
category.
Virus Detected and Not
Removed events from any
product.
Virus Detected (Heuristics)
and Not Removed events
from any product.
Repository update or replication
failed
Non-Compliant Computer
Detected events.
Configurations
Sends a notification message at most, once a day.
Sends a notification message at most, once a day.
Sends a notification message:
When the number of events exceeds 1000 within
an hour.
At most, once every two hours.
With the source system IP address, actual threat
names, and actual product information, if
available.
When the number of affected systems is at
least 500.
Sends a notification message:
When the number of events exceeds 1000 within
an hour.
At most, once every two hours.
With the source system IP address, actual threat
names, and actual product information, if
available.
When the number of affected systems is at
least 500.
Sends a notification message when any events are
received.
Sends a notification message when any events are
received from the Generate Compliance Event server
task.
155

Advertisement

Table of Contents
loading

Table of Contents