
DescriptionFile Name
Host Intrusion Prevention and ePO agent shared object modules*.so
Contains debug and error log fileslog directory
Installation history is written to /opt/McAfee/etc/hip-install.log. Refer to this file for any questions
about the installation or removal process of the Host Intrusion Prevention client.
Verifying the Linux client is running
If the client does not appear in the ePO console, for example, check that the client is running.
To do this, run this command:
ps –ef | grep Hip
Troubleshooting the Linux client
The Linux client has no user interface for troubleshooting operation issues. It does offer a
command-line troubleshooting tool,
hipts,
located in the opt/McAfee/hip directory. To use this
tool, you must provide a Host Intrusion Prevention client password. Use the default password
that ships with the client (abcde12345), or send a Client UI policy to the client with either an
administrator’s password or a time-based password set with the policy, and use this password.
Use the troubleshooting tool to:
• Indicate the logging settings and engine status for the client.
• Turn message logging on and off.
• Turn engines on and off.
Log on as root and run the following commands to aid in troubleshooting:
To do this...Run this command...
Obtain the current status of the client indicating which type of
logging is enabled, and which engines are running
hipts status
Turn on logging of specific messages types.hipts logging on
Turn off logging of all message types. Logging is off by default.hipts logging off
Display the message type indicated when logging is set to “on.”
Messages include:
hipts message <message name>:on
• error
• warning
• debug
• info
• violations
Hide the message type indicated when logging is set to “on.”
Message error is off by default.
hipts message <message name>:off
Display all message types when logging is set to “on.”hipts message all:on
Hide all message types when logging is set to “on.”hipts message all:off
Turn on the engine indicated. Engine is on by default. Engines
include:
hipts engines <engine name>:on
• MISC
• FILES
Working with Host Intrusion Prevention Clients
Overview of the Linux client
McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0104
Commenti su questo manuale