Again, I got a call from 2 different clients with similiar HIPS warnings regarding different files.
But… on the portal I can’t find them in any logs and can’t whitelist, blacklist, retrace the message…
I’m for sure that I’m not the only one…
Itarian, please comment. How can this be fixed and how can I see ALL the detected warnings that the users are getting.
As a managed system, I should see them also and interact with the Security Client, and not the user.
I keep posting these questions but get no answers…
Thanks. I will try to get the HIPS-logs from the device tomorrow.
But I want to note that there are a lot more entries not being logged and viewable from the portal.
So it would be strange that this isn’t noticed or known by the back-end team.
In brief: every action-window that the user gets, should be logged and viewable by the admin also so we/the admin, can whitelist/blacklist the requested threat.
As this is a managed security platform.
Currently HIPS logs can not be seen from the portal. We already have this feature on our roadmap, and it is currently under refinement process. We will share a possible ETA about this.
This is another basic function that’s missing and still not implemented after this time.
Can you tell when we can expect all the detected threats visible in the portal?
Hopefully not after months/years like other implementations because this is a crucial part of a managed security platform.
I couldn’t find it on the Roadmap…
@PremJkumar: I don’t think you need the HIPS logs anymore as it’s already a known issue?
That would be great.
Hereby the settings for this client:
Note: For this client I haven’t enabled the ‘Do not show popup alerts’ on purpose because of all the errors they had in the past.
It’s a dental office and a lot of times their programs were blocked and they couldn’t work and lost scanned images and work.
That’s why it should be handy if I could also see the detected warnings and white-/blacklist programs/files.
I contacted the client and unfortunately they’re not available for now.
When they’re online, I will export the logs and send them as requested.
Thanks for now.
Currently HIPS logs can not be seen from the portal. We already have this feature on our roadmap, and it is currently under refinement process. We will share a possible ETA about this.