Agent Status
In Agent Status, you can check information such as installation
info, user info, and policy application status of agents linked to physical/cloud
system.
Checking Agent Status List
From the Agent Status, you can check group info
of Physical System
and Cloud System
that have been created on the bottom of the domain to the left.
You can only check agent info that satisfies Advanced
Rule selected
for the chosen domain/group. From the list located below the Advanced Rule, you can check detailed info
such as Agent Info or Policy
Deployment, and you can send
a management command to the selected domain/group
or an individual agent, or export the selected
info as a file. Furthermore, you can click Show
Agents menu and select Agent Info
displayed on the menu to check detailed
info on the agents under the domain/group. You can also use Search feature to search for the desired information.
- Search: You can search the agent to check details.
To search for the agent to check details, click
from the top left side of the screen, select the item to search, and
enter the content. From the Keyword, you can search IP,
Connected IP, IP Range, MAC, Computer Name, Last Login User, User
Name, Agent ID, Department, Email, Phone Number, and Employee No.
Keyword is the default search option.
- Show Agents: You can check info of the agent
in a domain/group. Set the info that will be shown on the screen via
Show Agents in the Column Settings. From
the left of the Agent Status screen, you can select Domain or Group
and click Show Agents to display all
agents of the domain.
- Column Settings: You can set columns to display
on the agent list. Click Column Settings
on the side of Show Agents (
)
to select columns to show on the list of the screen.
- Agent Info: You can
check the agent info of the selected domain or group.
- Agent Issue Overview:
You can check the overview of issues on agents of the selected domain
or group. The issue condition settings show agent information that
match the issue condition set in Dashboard >
Summary > Flagged Agents >
Issue Condition Settings (
)
located on the side of Flagged Agents. The issue condition settings
can be checked in Flagged Agents.
- V3 Info: Displays V3
installation/policy application status.
- HIPS/Firewall Info:
You can check HIPS installation status or application status of IPS
and firewall.
- AC Info: You can check
AC installation status/application status.
- Policy Deployment:
You can check whether policy was applied by product license. If the
product is not installed, it will be shown as Not Installed.
Domain/Group
In Domain/Group, there is a physical system and cloud system under a
domain.
- Physical System: Info of the agent installed
in physical system. You can create a child group under physical system
and manage by group.
- Default Group: The
default group of physical system. Agent connected to the server belongs
to this group by default, and the Default Group cannot be removed.
- Cloud System: Info of the agent installed in
cloud system. You can create a group under cloud system and manage
by group.
- AWS: The default
group of cloud system. It is a group created based on the currently
supported CSP (Cloud Service Provider), and the child groups cannot
be moved.
- Azure: The default
group of cloud system. It is a group created based on the currently
supported CSP (Cloud Service Provider), and the child groups cannot
be moved.
Note
The linking of cloud system can be done in Settings > Cloud System.
Upon selecting the pre-set advanced rule, only the agents
that satisfy the advanced rule within the selected group will be displayed.
This works like a filter. You can click Expand
located on the side of the advanced rule combo box to check details of
the advanced rule (policy content, response type, excluded target). To
hide the details of the selected advanced rule, click Collapse.
- Details: Displays the detailed information of
the Advanced Rule.
- Response: This is the response that is taken
when an agent that meets the criteria of the set Advanced Rule is
detected. You can send notice to the detected agent or set individual
response by license.
- Exclusion: IP address excluded from Advanced
Rule. If an exclusion target is set, Set
will show, and if not, Not Set will show.
You can check the info of the agent of the selected domain
or group. The columns in the Agent Info only show info set in
Column Settings (
).
The method to check Agent info is as follows:
- Select Management
from the main menu on the top side of the web screen.
- From the menu, select Management
> Agent Status.
- Select Advanced
Rule info on the top side. Upon selecting Advanced Rule, the screen
will show info that is filtered according to the set Advanced Rule.
If not selecting Advanced Rule, select Disable
Advanced Rule.
- Select Agent Info
from the list box. If you selected a group, click Show
Agents to check the group the agent is in. If you click IP or Computer Name
of agent item, you can move to Agent
Details.
- Send Command: You can send management command
for the selected agent. You can check details of the commands in Send
Command.
- Export: You can export the information of the
current agent status as csv, xlsx, pdf file and save them.
- Show Agents: You can check info of the agent
in a domain/group.
- Column Settings: You can select columns
to display on the agent list. The default value of the Column Settings
for the agent info is: Connection/IP/Computer
Name.
- Connection: You can check the results by the
server connection status of the agents.
- Connected (
): The agent
is connected to server.
- Not Connected (
): The agent
is not connected to server.
- IP:
This is the IP address of the system where the agent is installed.
- Connected
IP: This is the IP address of the agent connected to server.
- Computer
Name: This is the computer name of the system where the agent is installed.
- System
Type: Shows the detailed info on the OS of the system where the agent
is installed. Shows the OS system type and the service pack type.
- OS:
This is the OS of the system where the agent is installed. You can
select among Amazon Linux 2, CentOS 7/8, Linux/Unix, Redhat Enterprise
Linux 7/8, Ubuntu 16/18/20, Windows Server 2012 R2 Datacenter x64,
Windows Server 2012 R2 Standard x64, Windows Server 2016 x64 and Windows
Server 2019 x64.
- Security
Agent Integrity: Shows security integrity check result for the agent
file in the agent-installed system.
- Not
Violated: The agent’s file is intact according to the integrity check
result.
- Violated:
The agent’s file is damaged according to the integrity check result.
- Unknown:
Cannot check the final result of the integrity check for the agent.
- Security
Agent Version: Shows the version of the Security Agent.
- Secondary
Update Server: Shows the secondary update setting.
- Group
Path: The path of the group the agent is in.
- Last
Connection: The time when the agent last connected to server.
- MAC:
The MAC address of the system where the agent is installed.
- Windows
Task Group: The name of the task group that can be check from the
registration info of Windows.
- Agent
ID: The unique ID given to the agent.
- Last
Login User: The info of the Windows account that last logged into
the agent-installed system.
- User
Name: The name of the user of the agent-installed system.
- Department:
The name of the department where the user of the agent-installed system
belongs.
- Email:
The user email address of the system where the agent is installed.
- Phone
Number: The user phone number of the system where the agent is installed.
- Employee
No.: The user employee number of the system where the agent is installed.
- OS
Language: This is the OS language of the system where the agent is
installed. e.g.) Korean (Republic of Korea)
- Modified:
Shows whether the user info was modified.
You can check the overview of issues on agents of the selected
domain or group. The issue condition settings show agent information that
match the issue condition set in Dashboard >
Summary > Flagged Agents > Issue
Condition Settings (
) located on the side of Flagged
Agents. The issue condition settings can be checked in Flagged
Agents. The method to check Agent Issue Overview is as follows:
- Select Management
from the main menu on the top side of the web screen.
- From the menu, select Management
> Agent Status.
- Select Advanced
Rule info on the top side. Upon selecting Advanced Rule, the screen
will show info that is filtered according to the set Advanced Rule.
If not selecting Advanced Rule, select Disable
Advanced Rule.
- From the list box, select Agent
Issue Overview. If you selected a group, click Show
Agents to check the group the agent is in. If you click IP or Computer Name
of agent item, you can move to Agent
Details. In the Agent Issue Overview, the following info are shown
along with the items shown in Agent Info.
- License Expired:
Shows the number of agents with expired license.
- Security Product
Integrity Violated: Shows the agents with integrity violated security
product.
- Policy Not Applied:
Shows the agents where server-sent policy is not applied.
- Security Product
Not Installed: Shows the agents with no security product installed.
- V3 Engine Outdated:
Shows the number of agents with outdated engine. The agents that have
not updated the engine to the latest version from the date set in
V3 Security Check > Last Engine Update are displayed.
- Manual scan not performed:
Shows the number of agents that have not performed manual scan. The
agents that did not perform a manual scan on the date set in V3
Security Check > Last Manual Scan
are displayed.
- Malware/Reputation-based
detections (Last 30 days): Shows the number of agents that detected
threat via Malware/Reputation-based detection in the last 30 days.
Displays V3 installation/policy application status. In V3 Info, the
following info are shown along with items shown in Agent
Info. The method to check V3 info is as follows:
- Select Management
from the main menu on the top side of the web screen.
- From the menu, select Management
> Agent Status.
- Select Advanced
Rule info on the top side. Upon selecting Advanced Rule, the screen
will show info that is filtered according to the set Advanced Rule.
If not selecting Advanced Rule, select Disable
Advanced Rule.
- Select V3 Info
from the list box. Check the content of each item. If you click IP or Computer Name
of agent item, you can move to Agent
Details. In V3 Info, the following info are shown additionally
along with items shown in Agent Info.
- Disk Usage: The rate
of disk usage.
- V3 Install Status:
The install status of the V3 product installed on the agent.
- Anti-Malware Policy
Status: The V3-related policy application status of the agent. Depending
on the policy’s applications status (
), In Progress(
),
or Fail (
) will show.
- Real-time Scan: Shows
whether the real-time scan feature of the V3 product installed on
the agent is in use. Depending on the usage status, Enabled (
)
or Disabled (
) will show.
- Engine Version: Shows
the engine version of the V3 product. e.g.) 2018.03.10.07
- Last engine update:
Shows the time when the V3 product's engine was last updated. e.g.)
03/12/2018 00:00:00
- Security Product
Installed On: The date when the V3 product was installed on the agent.
e.g.) 03/10/2018 15:40:30
- Last Scan: The time
when the V3 product's latest scan took place. e.g.) 02/14/2018 20:34:29
- Serial Number:
The serial number of the V3 product.
In Policy Deployment, you can check the application status of the policy
sent by the server to the agent. The following info are shown along with
the items shown in Agent Info. The columns in
the Policy Deployment only show the info set in Column Settings (
).
- Select Management
from the main menu on the top side of the web screen.
- From the menu, select Management
> Agent Status.
- Select Advanced
Rule info on the top side. Upon selecting Advanced Rule, the screen
will show info that is filtered according to the set Advanced Rule.
If not selecting Advanced Rule, select Disable
Advanced Rule.
- Select Deploy Policy
Info from the list box. Depending on
the policy application status, if a program or patch is not installed,
Not Installed (
)
will show, if a policy is applied, In Progress (
) will show,
and if the policy has failed to apply, Fail
(
) will show. If a policy has been applied, Success (
) will show,
and if an individual policy has been applied, Success
(Individual Policy) (
)
will show. If you click IP or Computer
Name of agent item, you can move to Agent Details. The following
info are shown along with the items shown in Agent
Info.
- Security Agent Policy:
Shows the application status of a security agent policy.
- Anti-Malware Policy:
Shows the application status of a V3-related policy sent from server.
- HIPS Agent Policy:
Shows the application status of a HIPS policy sent from server.
- IPS Agent Policy:
Shows the application status of an IPS policy sent from server.
- Firewall Agent Policy:
Shows the application status of a firewall policy sent from server.
- AC Agent Policy:
Shows the application status of an AC agent policy sent from server.
- AC Policy: Shows
the application status of an AC policy sent from server.
Displays HIPS installation/policy application status. In HIPS/Firewall
Info, the following info are shown along with items shown in Agent
Info. The method to check HIPS/Firewall info is as follows:
- Select Management
from the main menu on the top side of the web screen.
- From the menu, select Management
> Agent Status.
- Select Advanced
Rule info on the top side. Upon selecting Advanced Rule, the screen
will show info that is filtered according to the set Advanced Rule.
If not selecting Advanced Rule, select Disable
Advanced Rule.
- Select HIPS/Firewall Info
from the list box. Check the content of each item. If you click IP or Computer Name
of agent item, you can move to Agent
Details. In HIPS/Firewall Info, the following info are shown along
with items shown in Agent Info.
- HIPS Connections:
You can check the results by the server connection status of HIPS.
Depending on the connection status, Connected, Not Connected, or Not
Installed will show.
- HIPS Version: Shows
the version of the HIPS product. e.g.) 1.0.0.3 (Build 520)
- IPS Settings: You
can check the results by the settings status of IPS. Depending on
the settings status, Emergency OFF, OFF, or ON will show.
- Signature Version:
Shows the version of the signature. e.g.) 2020.05.14.4
- Applied Signature:
Shows the number of signatures with applied policy.
- Firewall Settings:
You can check the results by the settings status of firewall. Depending
on the settings status, Emergency OFF, OFF, or ON will show.
- Applied Recommended
Signature: Shows the number of signatures where policy application
is recommended.
Displays AC installation/policy application status. In AC Info, the
following info are shown along with the items shown in Agent
Info. The method to check AC info is as follows:
- Select Management
from the main menu on the top side of the web screen.
- From the menu, select Management
> Agent Status.
- Select Advanced
Rule info on the top side. Upon selecting Advanced Rule, the screen
will show info that is filtered according to the set Advanced Rule.
If not selecting Advanced Rule, select Disable
Advanced Rule.
- Select AC Info
from the list box. Check the content of each item. If you click IP or Computer Name
of agent item, you can move to Agent
Details. In AC Info, the following info are shown along with the
items shown in Agent Info.
- AC Connections: You
can check the results by the server connection status of AC. Depending
on the connection status, Connected, Not Connected, or Not Installed
will show.
- AC Settings: You
can check the results by the settings status of AC. Depending on the
settings status, In Progress, Lockdown, OFF, or Not Installed will
show.
- AC version: Shows
the version of the AC product. e.g.) 1.0.0.3 (Build 520)
- AC Engine Version:
Shows the engine version of the AC product. e.g.) 3.2.0.49 (Build
754)
Related Information