Security Compliance

Integrate McAfee ePolicy Orchestrator (ePO) with SolarWinds SEM

This article outlines the procedures for configuring McAfee ePolicy Orchestrator (ePO) 4.5 and later to send logs to SEM using SNMP, and configuring your SEM appliance to accept the logs and process them for storage and monitoring.

First published date

10/10/2018 1:52 AM

Last published date

10/30/2025 10:17 PM

Overview

This article describes how to configure McAfee ePolicy Orchestrator (ePO) 4.5 and later to send logs to your Security Event Manager (formerly Log & Event Manager) appliance using SNMP, and configure your SEM appliance to accept the logs and process them for storage and monitoring.

Environment:
  • SEM
  • McAfee ePolicy Orchestrator (ePO) 4.5 and later
  • V2 SNMP (no community string needed)

Product section

Security Event Manager

Resolution

  1. To configure ePO to recognize your SEM appliance as an SNMP server and configure an automatic rule to send traps, please refer to the ePO Product Guide.
  2. To configure your SEM manager to accept SNMP traps:
    1. Connect to your appliance using a virtual console or SSH client.
    2. Access the CMC prompt:
      1. Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
      2. SSH Client: Log in using your CMC credentials.
    3. At the cmc> prompt, enter service.
    4. At the cmc::scm# prompt, enter snmp.
    5. To confirm your entry, press Enter.
    6. Would you like to ENABLE the SNMP Trap Logging Service? [Y/n] y
    7. Would you like to ENABLE the SNMP Request Service? [Y/n] n
    8. You will see the message, The SNMP Trap Logging Service is started.
    9. To log out of your SEM virtual appliance, enter exit.
  3. To configure the ePolicy Orchestrator (ePO) connector on your SEM Manager:
    1. Open your SEM console, and then log in as an administrator.
    2. Click the Manage menu, and then select Appliances.
    3. Click the gear icon next to your SEM appliance (left), and then select Connectors.
    4. In the Connector Configuration window, enter ePolicy Orchestrator in the search box at the top of the Refine Results pane.
    5. Click the gear icon next to the ePolicy Orchestrator (ePO) 4.5+ connector, and then select New.
    6. Enter a custom Alias or accept the default.
    7. Click Save.
    8. Click the gear icon next to the new connector, denoted by an icon in the Status column, and then click Start.
    9. To close the Connector Configuration window, click Close.

    -OR- In the HTML5 Console:

    1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
    2. In the search box, enter ePolicy Orchestrator.
    3. Select the ePolicy Orchestrator (ePO) 4.5+ connector, and then click Add Connector.
    4. Enter a new name, or maintain the default, and then click Add.
    5. Under Configured connectors, select the connector, and then click Start.
  4. After the connector starts, test your integration using a trusted antivirus test site, such as www.eicar.org