Respond to policy events

Prev Next

Set up an automatic response in ePO - On-prem that is filtered to see only policy events.

  1. Select MenuAutomationAutomatic Responses to open the Automatic Responses page.

  2. Click New Response.

  3. Enter a Name for the response, and an optional Description.

  4. Select ePO Notification Events for the Event group, and Client, Threat, or Server for the Event type.

  5. Click Enabled to enable the response, then click Next.

  6. From Available Properties, select Event Description.

  7. Click ... in the Event Description row and choose an option:

    • Agent failed to collect properties for any point products — This event is generated and forwarded when a property collection failure first occurs. A subsequent success event is not generated. Each failing managed product generates a separate event.

    • Agent failed to enforce policy for any point products — This event is generated and forwarded when a policy enforcement failure first occurs. A subsequent success event is not generated. Each failing managed product generates a separate event.

  8. Enter remaining information into the filter as needed, then click Next.

  9. Select Aggregation, Grouping, and Throttling options as needed.

  10. Choose an action type and enter a behavior depending on the action type, then click Next.

  11. Review the summarized response behavior. If correct, click Save.

The automatic response performs the described action when a policy event occurs.