Use an Event Rule to Automatically Restore Devices to Normal Enforcement
book
Article ID: 286768
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Steps to create an Event Rule to automatically restore an endpoint to normal Enforcement Level after remaining in Local Approval longer than desired.
Environment
- App Control Console: All Supported Versions
- App Control Agent: All Supported Versions
Resolution
Part 1 of 2 - Configuring the Alert
- Log in to the Console and navigate to Tools > Alerts > edit "Local Approval Alert".
- Set the General > Status: Enabled
- Set the Criteria > Time Period accordingly. (Default is 1 hour)
- Set the Auto Reset to use the following:
- Status: Enabled
- Reset After: 1 Minute
- Click Save & Exit
Warning: Email notifications for this Alert are not recommended if regularly moving bulk numbers of Agents.
- The Alert will generate for all machines matching the criteria.
- The Event Rule can only move one machine at a time.
- If multiple machines are moved at the same time this may cause duplicate Emails to be delivered.
|
Part 2 of 2 - Creating the Event Rule
- Navigate to Rules > Event Rules > Create Rule.
- Use the following details:
- Rule Name: Restore Normal Enforcement (or something memorable)
- Status: Enabled
- Event Properties: Policy > is: Local Approval Policy
- Event Properties: Subtype > is: Alert triggered
- Action: Move Computer
- Target: Restore to Normal Enforcement Level
- Click Save & Exit
Additional Information
- Each Event Rule is designed to work with one Trigger at a time.
- If multiple endpoints are moved from Normal to Local Approval at the same time, only one endpoint will count as the Trigger.
- Only the Triggered endpoint will be moved back to Normal Enforcement
Feedback
thumb_up
Yes
thumb_down
No