Enabling UDP Network Event Capture

Prev Next
To enable UDP network event capture for all of your host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.

  4. Select the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.

    Policy_RTID_Enable.png
  6. In the Events section, toggle the Capture UDP Events ON/OFF switch to ON

    Policy_RTID_UDP_Enable.png
  7. Click Save.

To enable UDP network event capture for selected host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the link for the custom policy you want to modify.

  4. Select the Real-Time Indicator Detection tab.

    Policy_RTID_Tab.png
  5. Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.

    Policy_RTID_Enable.png
  6. In the Events section, toggle the Capture UDP Events ON/OFF switch to ON

    Policy_RTID_UDP_Enable.png
  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.