Overview
McAfee ePolicy Orchestrator (ePO) plugin provides access to retrieve System Tree information, manage tags, and execute existing queries within ePO.
Functionality
The Security Flow McAfee ePolicy Orchestrator Plugin exposes the ability to
- retrieve group information,
- retrieve system information,
- retrieve tag information,
- apply a tag to systems,
- clear tags from systems, and
- execute queries define in ePO.
Instance Configuration Parameters
A system-wide unique identifier for this plugin instance used to locate the service.
A unique name to describe the ePO System.
A system-wide unique identifier for this plugin instance used to locate the service.
Checkbox: When using TLS communication, ensure the ePO certificate is authorized by an installed CA certificate.
ePO server IP address or hostname.
ePO server port; Choose between 1-65535.
Username for the ePO server.
Password for the username on the ePO server.
Re-type valid password for the user name on the ePO server.
Flow Node
The display name of the node within the flows.
System-wide unique ID of the plugin instance.
Configuration option determining the type of operation to perform:
- Find Groups: Retrieves information on the groups matching the
Search Text
. If theSearch Text
is blank, all groups are returned. - Find System(s): Retrieves information on the systems matching the
Search Text
. TheSearch Text
finds systems in the McAfee ePO System Tree by name, IP address, MAC address, user name, agent GUID, or tag. IfLimit Search To Computer Name
is checked, only the system name is searched. - Find Tags: Retrieves information on the tags matching the
Search Text
. If theSearch Text
is blank, all tags are returned. - Apply Tag: Applies a tag to the specified
System(s)
. - Clear Tag: Clears a tag from the specified
System(s)
. - Clear All Tags: Clears all tags from the specified
System(s)
.
Successful results for an action are placed in msg.payload.epo.[uniqueId].response
.
The Search Text
used to locate the matches, for the find related Action
codes.
When performing a Find System(s)
Action
, this limits the search to the computer name.
On of three possible types:
- Comma-separated list of Computer Names or IP addresses.
- An array of zero or more Computer Names or IP addresses.
- An array of zero or more system objects containin the
EPOComputerProperties.ComputerName
attribute, such as those returned by theFind System(s)
action.
Existing tag defined in the ePO system.
The display name of the node within the flows.
System-wide unique ID of the plugin instance.
Name of the query to be executed (case-sensitive). The list of queries are available on the McAfee ePO web portal.
Name given to the CSR report server’s database. Blank by default.
Metro Office Park
2950 Metro Drive, Suite 104
Bloomington, MN 55425
Phone: +1 952-500-8921
©Nevelex Labs, LLC. 2018-2024, All Rights Reserved.
EULA