Setting Filters For The Rule; Setting Thresholds Of The Rule - McAfee EPOCDE-AA-BA - ePolicy Orchestrator - PC Product Manual

Product guide
Table of Contents

Advertisement

Task
1
Click Menu | Automation | Automatic Responses, then click Actions | New Response, or Edit next to an existing
rule.
The Response Builder wizard opens.
Figure 18-1 Notifications Rules page
2
On the Description page, type a unique name and any notes for the rule.
Rule names on each server must be unique. For example, if one user
creates a rule named Emergency Alert, no other user (including global
administrators) can create a rule with that name.
From the Language menu, select the language the rule uses.
3
4
Select the Event group and Event type that trigger this response.
Select whether the rule is Enabled or Disabled next to Status.
5
Click Next.
6

Setting filters for the rule

Use this task to set the filters for the response rule on the Filters page of the Response Builder wizard.
For option definitions click ? in the interface.
Task
From the Available Properties list, select the desired property and specify the value to filter the
1
response result.
Available Properties depend on the event type and event group selected
on the Description page of the wizard.
2
Click Next.

Setting thresholds of the rule

Use this task to define when the event triggers the rule on the Aggregation page of the Response
Builder wizard.
A rule's thresholds are a combination of aggregation, throttling, and grouping.
Responding to events in your network
Creating and editing Automatic Response rules
®
®
McAfee
ePolicy Orchestrator
4.6.0 Software Product Guide
18
223

Advertisement

Table of Contents
loading

This manual is also suitable for:

Epolicy orchestrator 4.6.0

Table of Contents