
Managing Your Protection
Management of a Host IPS deployment includes monitoring, analyzing, and reacting to activities;
changing and updating policies; and performing system tasks.
Contents
Management of information
Management of policies
Management of systems
Management of information
After you have installed Host Intrusion Prevention you can track and report on security issues
that arise in your environment. Use the dashboards to get a daily view of the security situation
or run queries for detailed information on particular issues.
Host IPS activities and dashboards
Dashboards, a collection of monitors, are an essential tool for managing your environment.
Monitors can be anything from a chart-based query to a small web-application, like the MyAvert
Threat Service. You can create and edit multiple dashboards, provided you have the permissions.
Use any chart-based query as a dashboard that refreshes at a specified frequency, so you can
put your most useful queries on a live dashboard.
Host Intrusion Prevention provides a default dashboard with these monitors:
• Firewall Status
• Host IPS Status
• Service Status
• Count of IPS Client Rules
• Content Versions
• Top 10 NIPS Events by Source IP
For more information about creating and using dashboards, refer to the ePolicy Orchestator
4.0 documentation.
Queries for Host IPS activities
Host Intrusion Prevention includes query functionality through ePolicy Orchestrator. You can
create useful queries from events and properties stored in the ePO database or use predefined
queries.
13McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0
Comentarios a estos manuales