Insert email in Automatic Response for Solidcore Policy Discovery events

Prev Next

As an Administrator, you can configure an Automatic Response in ePO - On-prem to insert user's email address and send notifications directly to users who request approval for blocked applications. This is specific to Solidcore Policy Discovery events only.

Prerequisites

Before you begin, ensure the following:

  1. ePO 5.10 SP1 Update 5 is installed.

  2. Trellix Application and Change Control extension (TACC extension 8.4.3 and later) and package (for Solidcore) are installed on all required endpoints.

  3. Solidcore extension is checked-in on the ePO Extensions page.

  4. Email server settings are configured in ePO to send out notifications.

    1. Go to MenuConfigurationServer SettingsEmail Server.

    2. Enter SMTP server name, port, and sender address.

    3. Enable TLS, if required, and Save.

  5. You have permission to manage Automatic Response.



Configure Automatic Response to insert an email
  1. Create an Automatic Response Rule for Solidcore event in ePO - On-prem.

    1. In the ePO - On-prem console, go to MenuAutomationAutomatic Responses.

    2. Click New Response.

    3. On the Description page, enter the following details:

      • Name: A name given to this Automtic Response.

      • Event Group: Solidcore Events

      • Event Type: Policy Discovery Event

      • Status: Enabled

    4. Click Next.

    5. (optional) Add filters.

    6. (optional) Configure Aggregation.

    7. Configure Action with Insert Email option

      1. On the Actions page, select Send Email from the drop-down.

      2. Under Recipients, click the Insert option. This inserts the user's email address that was added as a part of Request Approval.

      3. Customize the Subject and Body using available variables (For example, $UserEmail$, $FileName$, and so on).

      4. Click Next and save the Automatic Response rule.

  2. Generate a Solidcore Policy Discovery event from client system.

    1. Install the Trellix Application and Change Control package on endpoint systems from ePO - On-prem.

    2. On the endpoint system, execute the application that is not on the corporate allow list. For example, Putty.exe.

      A message is displayed stating that the application is not on the corporate allow list and is not allowed to run.

    3. Click on the tray icon and select Quick SettingsApplication and Change Control Events.

    4. Locate the blocked application event (Putty.exe) in the events log and click Request Approval.

    5. Enter the user's email address in the provided field and submit the request. This action generates two events for Solidcore Policy.

    6. Navigate to ePOApplication ControlPolicy Discovery and view these events:

      • Received - with user email

      • Not Received - without email.

  3. The response is automatically triggered when a Solidcore Policy Discovery event matches the configured automatic response. The user who submitted the request will then receive an email notification.

    Note

    Automatic Response is triggered only for Received approval requests that include a user email. You can modify the default configuration to enable responses for both Received and Not Received requests.

    • Global actions — If an Automatic Response is configured, and before the policy is applied at the endpoint, a new request is received for an already approved Policy Discovery request, an Automatic Response triggers for the new request, and the associated user email (if available) is notified.

    • Custom actions — The first time a custom action is taken on a request (if the status is Received and a user email is available), the associated users are notified. If another request for the same file/groupedReqID appears under Pending Requests, then on taking a custom action, only the user emails associated with the newly received request are notified. Users who have already been notified do not receive another notification.

  4. Trigger the response from the Policy Discovery Event page.

    1. Go to Application ControlPolicy Discovery.

    2. Locate the event that includes the user email as Received.

    3. Select the event and select ActionsAllow File Globally. This action allows the blocked application and logs the event and Automatic Response is triggered.

    4. The user who submitted the request receives an email notification.

  5. Verify execution in the Server Task log.

    1. Go to MenuAutomationServer Task Log.

    2. Verify the status of the Automatic Response to confirm that the email was sent.