McAfee HISCDE-AB-IA - Host Intrusion Prevention Product Manual page 15

Product guide for use with epolicy orchestrator 4.5
Table of Contents

Advertisement

Managing Your Protection
Information management
• Blocked Attackers
• Client Version
• Content Version
• Firewall Adaptive Mode Status
• Firewall Fault (Errors)
• Firewall Inbound Learn Mode Status
• Firewall Outbound Learn Mode Status
• Firewall Rule Count
• Firewall Status
• Host IPS Fault (Errors)
• Host IPS Status
Install Directory
Pre-defined queries
In addition to custom queries, you can use several pre-defined queries as is, or edit them to
obtain just the information you need. Select from these Host IPS predefined queries:
HIP Query
Client Rules By Process
Client Rules By Process/Port
Range
Client Rules By Process/User
Client Rules By
Protocol/System Name
Client Rules By Protocol/Port
Range
Client Rules by
Protocol/Process
Client Versions
Clients Pending Restart
Content Versions
Count of FW Client Rules
Count of IPS Client Rules
Desktop High Triggered
Signatures
Desktop Medium Triggered
Signatures
Desktop Low Triggered
Signatures
Events From Host IPS Trusted
Networks
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
• Language
• Local Exception Rule Count
• Network IPS Status
• Pending Reboot
• Plug-in Version
• Product Status
• Service Running
• Hotfix/Patch Version
• Product Version
• Service Pack
• Host IPS Event Info (Hidden, Read)
Signature Name
Summary
Displays firewall client rules listed by process.
Displays firewall client rules listed by process and port range.
Displays firewall client rules listed by process and user.
Displays firewall client rules listed by protocol and system name.
Displays firewall client rules listed by protocol and port range.
Displays firewall client rules listed by protocol and process.
Displays top three client versions with a single category for all other versions.
Displays managed systems where Host IPS is deployed and the installer needs to
restart the system.
Displays top three content versions with a single category for all other versions.
Displays the number of Firewall client rules created over time.
Displays the number of IPS client rules created over time.
Displays the top 10 most triggered IPS signatures of High Severity (Critical).
Displays the top 10 most triggered IPS signatures of Medium Severity (Warning).
Displays the top 10 most triggered IPS signatures of Low Severity (Notice).
Displays events generated by systems within Host IPS trusted networks.
15

Advertisement

Table of Contents
loading

This manual is also suitable for:

Host intrusion prevention 8.0

Table of Contents