Parameters
Query
have no allow/block action. IPS Catalog rules and
groups have the
leafNodeId filter value set to 0,
•
Leaf Node ID
•
Local Services
so to view firewall client rules only, set the
leafNodeId filter value to
> 0.
•
Log Status
•
IP Protocol
•
Match Intrusion
•
Media Type
•
Name
•
Note
•
Remote Services
•
Rule ID
•
Schedule End
•
Schedule Start
•
Switch When Expired
•
Transport Protocol
Host IPS 8.0 Firewall Client Rule Executables
•
Fingerprint
•
Name
•
Note
•
Path
•
Rule ID
•
Signer Name
Host IPS 8.0 IPS Client Rules
•
Creation Date
•
Description
•
Executable Name
•
Executable Path
•
Fingerprint
•
Full Executable Name
•
Include All Executables
•
Include All Signatures
•
Include All Users
•
Last Modified Date
•
Local Version
•
Reaction
•
Signature ID
•
Signer Name
•
Status
•
User Name
Host IPS 8.0 IPS Exceptions
•
IPS Exception Rule
•
IPS Rules Policy
Common Host IPS properties
The Host IPS custom queries and some of the other custom queries allow you to include these
Host IPS properties:
• IPS Adaptive Mode Status
• Agent type
Managing Your Protection
Information management
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
14