Security Compliance
Integrate McAfee ePolicy Orchestrator (ePO) with SolarWinds SEM
This article outlines the procedures for configuring McAfee ePolicy Orchestrator (ePO) 4.5 and later to send logs to SEM using SNMP, and configuring your SEM appliance to accept the logs and process them for storage and monitoring.
First published date
Last published date
Overview
Environment:
- SEM
- McAfee ePolicy Orchestrator (ePO) 4.5 and later
- V2 SNMP (no community string needed)
Product section
Resolution
- To configure ePO to recognize your SEM appliance as an SNMP server and configure an automatic rule to send traps, please refer to the ePO Product Guide.
- To configure your SEM manager to accept SNMP traps:
- Connect to your appliance using a virtual console or SSH client.
- Access the CMC prompt:
- Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
- SSH Client: Log in using your CMC credentials.
- At the cmc> prompt, enter service.
- At the cmc::scm# prompt, enter snmp.
- To confirm your entry, press Enter.
- Would you like to ENABLE the SNMP Trap Logging Service? [Y/n] y
- Would you like to ENABLE the SNMP Request Service? [Y/n] n
- You will see the message, The SNMP Trap Logging Service is started.
- To log out of your SEM virtual appliance, enter exit.
- To configure the ePolicy Orchestrator (ePO) connector on your SEM Manager:
- Open your SEM console, and then log in as an administrator.
- Click the Manage menu, and then select Appliances.
- Click the gear icon next to your SEM appliance (left), and then select Connectors.
- In the Connector Configuration window, enter ePolicy Orchestrator in the search box at the top of the Refine Results pane.
- Click the gear icon next to the ePolicy Orchestrator (ePO) 4.5+ connector, and then select New.
- Enter a custom Alias or accept the default.
- Click Save.
- Click the gear icon next to the new connector, denoted by an icon in the Status column, and then click Start.
- To close the Connector Configuration window, click Close.
-OR- In the HTML5 Console:
- In the SEM Events Console, navigate to Nodes > Manager Connectors.
- In the search box, enter ePolicy Orchestrator.
- Select the ePolicy Orchestrator (ePO) 4.5+ connector, and then click Add Connector.
- Enter a new name, or maintain the default, and then click Add.
- Under Configured connectors, select the connector, and then click Start.
- After the connector starts, test your integration using a trusted antivirus test site, such as www.eicar.org.