MONITORING MODES
To modify the VSP Host Monitoring mode:
-
On the Host Monitoring page, click the below icon
-
Select all the required hosts and click Manage Monitoring Mode
-
Select the required option
-
Protect – Processes and libraries (if library monitoring is enabled) that are not found in the process profile are suspended/blocked immediately. They are not acted upon until the user adds the detected errant process/library to the allowlist or deletes it on CMS.
-
In cases where the errant process/library is added to the allowlist, the process/library is resumed
-
In cases where the errant process/library is deleted from the allowlist, the process (or the process containing the errant library) is killed
-
An un-allowlisted process on Windows is NOT allowed to execute
-
Click Move to Protect Mode. Click YES on the confirmation screen
-
-
Detect – Processes and libraries (if library monitoring is enabled) that are not found in the process profile are reported immediately to CMS.
-
The processes/libraries are not stopped from executing
-
If additional protection actions are configured in a protection profile, these actions are executed in response to a reported incident
-
Click Move to Detect Mode. Click YES on the confirmation screen
-
-
Disable – The selected host is NOT monitored. Click Disable Monitoring. Click YES on the confirmation screen
NOTE:
Protect, Detect or Disable options can be chosen for each host
-
-
Click CLOSE