Default rules
ePolicy Orchestrator provides six default rules that you can enable for immediate use while you
learn more about the feature.
NOTE:
Once enabled, the default rules send notification messages to the email address you
provided in the ePO installation wizard.
Before enabling any of the default rules:
• Specify the email server (at Configuration | Server Settings) from which the notification
messages are sent.
• Ensure the recipient email address is the one you want to receive email messages. This
address is configured on the Notifications page of the wizard.
Default notification rules
Configurations
Associated Events
Rule Name
Sends a notification message at most, once a day.
Any events from any unknown
products.
Daily unknown product
notification
Sends a notification message at most, once a day.
Any event of an unknown
category.
Daily unknown category
notification
Sends a notification message:
Virus Detected and Not
Removed events from any
product.
Virus detected and not
removed
•
When the number of events exceeds 1000 within
an hour.
•
At most, once every two hours.
•
With the source system IP address, actual threat
names, and actual product information, if
available.
•
When the number of affected systems is at
least 500.
Sends a notification message:
Virus Detected (Heuristics)
and Not Removed events
from any product.
Virus detected heuristics and
not removed
•
When the number of events exceeds 1000 within
an hour.
•
At most, once every two hours.
•
With the source system IP address, actual threat
names, and actual product information, if
available.
•
When the number of affected systems is at
least 500.
Sends a notification message when any events are
received.
Repository update or replication
failed
Repository update or
replication failed
Sends a notification message when any events are
received from the Generate Compliance Event server
task.
Non-Compliant Computer
Detected events.
Non-compliant computer
detected
Planning
Before creating rules that send notifications, save time by planning:
Sending Notifications
Planning
155
McAfee ePolicy Orchestrator 4.0.2 Product Guide