Hi,
I'm looking to run a client task to search for a specific file / folder on workstations that will scan for a particular file or not. I have the client task running and can see if the file was scanned or not in the ondemandscanactivity log file.
Is there anyway on the EPO server to get a report created that will show me if a workstation has this file or not? If there is a way can you send on instructions?
Regards
Solved! Go to Solution.
It would depend on what action you have set to take for the PUP item. This is defined within the policy is using a policy based task / or within the task if using a custom task. You will however want to use a policy based task as custom tasks don't generate events. So would not achieve the desired results.
The only I way I can think that you could achieve this would be by defining the certain file as a PUP (within the ENS TP Options policy) and then running an ODS task for PUPs.
Thanks Chealey,
Is there specific instructions on how to do this? If you define this file as a pup file the file wont be deleted and the pup tag can always be removed after?
Hi @fattonymaximus ,
Just saw @Former Member 's response. Excellent way to do it. Apologies for having missed it. When defined as pup, you can combine the steps above for targeted scan and use this document to ensure PUP detection is enabled for On Demand Scan that you are going to perform. Here is how you can specify your own PUP file. Hope this helps!
Here is a similar post that should definitely help you!
Although file level scan events are view-able using your logs, ePO does not deal with logs. They deal with Events. Events, to ensure that they are sizable, can not have file level information on it as far as ENS reporting goes and hence ePO may not be able to show it AFAIK.
You can, however, send a targeted scan using customer on demand scan to scan exactly that specific file (select Scan location as "File or folder" and specify the file or location with full path).
I am afraid though these events may not tell you the presence of this file. So if your goal is to find if a non malicious file is present in a machine or not, I am afraid that cannot be done via Scan task. I sincerely hope this answers your query!
Thanks All,
If i do this, will it be a case that the file could get deleted from either a policy based on demand scan or a policy based on access scan or even a custom based on demand or on access scan?
I don't want this to happen of course.
Regards
It would depend on what action you have set to take for the PUP item. This is defined within the policy is using a policy based task / or within the task if using a custom task. You will however want to use a policy based task as custom tasks don't generate events. So would not achieve the desired results.
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: