Actions page (Response Builder)

Prev Next

Specify one or more actions to take in response to an event. The event type you specified in the Description page of the Response Builder determines available actions. You can specify multiple actions to take by clicking +. Each action must be configured using the action options defined in the table.

Create Issue action

Option definitions

Option

Definition

Create issue of the type

Select the type of issue that you want to create.

Name

Type a name for the issue.

Note

Using the Insert variable lists you can insert variables in the email with descriptions of the event.

Description

Type a description for the issue.

Note

Using the Insert variable lists, you can insert variables in the email with descriptions of the event.

State

Select a state from the list.

Priority

Select a priority from lowest to highest from the list.

Severity

Select a severity from lowest to highest from the list.

Resolution

Select a resolution from the list.

Assignee

Type the email of the assignee of the issue.



Execute Server Task action

Option definitions

Option

Definition

Task to execute

Select the task that you want to occur when this response is triggered.



Run External Command action

Option definitions

Option

Definition

Registered executable

Select the registered executable that you want to run when this response is triggered. Create the registered executable before adding it to this response action.

Arguments

Type arguments into the Arguments field.

Note

Make sure you use the correct syntax for your executable.



Run System Command action

Option definitions

Option

Definition

Apply Tag

Runs the system command to assign tags based on the following:

  • Server — Applies the tag on all managed servers.

  • Workstation — Applies the tag on all managed workstations.

Assign Policy

Runs the system command to assign a policy based on the following:

  • Product — The product selected.

  • Category — The category selected.

  • Policy — Assigns the policy by resetting the policy inheritance and using the product and category configured, or breaking the policy inheritance and using the policy selected from the drop-down list.

Clear Tag

Runs the system command to remove the following tags:

  • Server — Managed server tags.

  • Workstation — Managed workstation tags.

  • Clear all — All tags.

Delete Systems

Runs the system command to remove agents and delete systems from management.

Deploy Trellix Agent

Runs the system command to deploy the Trellix Agent using the following:

  • Abort after — Specifies the number of minutes before canceling the attempt.

  • Agent version — Specifies the version of the agent to send and install on the selected systems. Agent versions available depend on which agent installation packages are checked in to the Main Repository.

  • Credentials for agent installation — Specifies the domain name, user name, and password of the user account with which to install the agent on selected systems.

  • Installation options — Specifies the systems to deploy the Trellix Agent to based on the following:

    • Install only on systems that do not have an agent — Sends the agent installation package only to systems without an agent installed. When deselected, sends the agent installation package to all selected systems, regardless of whether the agent is already installed on them.

    • Force installation over existing version — Replaces existing agents within the selected group with the selected versions. This option is not available when you select Install only on systems that do not have an agent.

  • Installation path — Specifies the path on the client system (default is <system_drive>\McAfee\Common Framework) where you want to install the agent. The location you specify must exist on managed systems.

  • Number of attempts — Specifies the number of attempts before canceling the attempt.

  • Push Agent using — Specifies the Agent Handler to use based on the following selection:

    • Using the selected Agent Handler from the drop-down list.

    • Using all Agent Handlers

  • Retry interval — Specifies the number of seconds between attempts to install the agent.

Exclude Tag

Runs the system command to exclude server and workstation tags.

Move Systems

Runs the system command to move managed systems using the following:

  • System Tree group — Browse to the group to move.

  • When these systems are moved to the new location — Specify the System Tree sorting using the following:

    • Disable System Tree sorting on these systems.

    • Enable System Tree sorting on these systems.

    • Do not change the System Tree sorting status for any of these systems.

Resort Systems

Runs the system command to resort the managed systems.

Run Client Task Now

Runs the system command to run a client task using the following:

  • Abort after — Specifies the number of minutes before canceling the task.

  • Connect Using — Specifies the handler to use for the task.

  • Number of attempts — Specifies the number of attempts before canceling the task.

  • Product — The product selected.

  • Randomization — Specifies the randomization intervals, in minutes, to mitigate the bandwidth impact.

  • Retry interval — Specifies the number of seconds between attempts to run the task.

  • Stop Task on the Client After — Specifies the number of minutes before the attempt to run the task is canceled.

  • Task — Select the task from the list.

  • Task Type — Select the task type from the list.

Sensor Blacklist Management

Runs the system command to add or remove sensors from the blacklist.

Set User Properties

Runs the system command to set the description.

Transfer Systems

Runs the system command to transfer systems between ePO - On-prem servers.

Wake Up Agents

Runs the system command to wake up agents using the following:

  • Abort after — Specifies the number of minutes or hours before canceling the wake-up attempt.

  • Force complete policy and task update — Forces policy and task updates during the agent wake-up.

  • Get full product properties in addition to system properties — Select to retrieve all agent properties. Otherwise, only minimal product properties and system properties are sent.

  • Number of attempts — Specifies the number of attempts before canceling the agent wake-up.

  • Randomization — Specifies the randomization intervals, in minutes, to mitigate the bandwidth impact.

  • Retry interval — Specifies the amount of time between attempts to run the wake-up task. The interval can be provided in seconds, minutes, and hours.

  • Wake up Agent using — Specifies the Agent Handler to use based on the following selection:

    • Using the last connected Agent Handler

    • Using all Agent Handlers

  • Wake-up call type — Specifies the call type as either:

    • Agent Wake-Up Call

    • SuperAgent Wake-Up Call



Send Email action

Option definitions

Option

Definition

Recipients

Enter or select the recipient of the event email.

Importance

Select the importance of the email.

Subject

Enter the subject that appears in the event email.

Note

Using the Insert variable lists, you can insert variables in the email with descriptions of the event.

Body

Enter the text that appears in the event email.

Note

Using the Insert variable lists, you can insert variables in the email with descriptions of the event.



Send SNMP trap action

Option definitions

Option

Definition

SNMP Servers

Select an SNMP server from the preconfigured list.

Note

Before using this feature, add your SNMP servers to Automatic Responses, and import the .mib files.

Available Types

Select the SNMP trap type value to send using the >> button to move it to the Selected Types list.