Data Loss Prevention

 View Only
  • 1.  Monitoring Application on Endpoint

    Posted Dec 08, 2021 11:01 AM
    Dear all
    I'm looking for some really basic understanding and information how to implement monitoring for one specific application on Endpoints. The endpoints are located in a specific VDI with a specific IP range. 
    So far I've added my .EXE in the "Global application monitoring". I've setup an "Agent Configuration". I've added within the channel filter my IP Range.
    I have created an "Agent Group" and assigned the "Agent Configuration".
    The part that I don't understand is. How do I make sure that only the clients I want to monitor get this config and none of the others. My only unique attribute is that those clients have a specific IP Range. Any user can get access to the VDI, so I cannot think of any useful user attributes. I've configured in the agent group the endpoint server.
    Thanks for further explanation and help.
    André


  • 2.  RE: Monitoring Application on Endpoint

    Posted Dec 09, 2021 08:01 AM
    Hello Andre,

    If you have some attributes in the computer object in AD you can use to discriminate the VDI  (it can also be the start of the computername for example) you can give a try to Agent attributes.
    The IP of the workstation is not something you can use to push a specific endpoint configuration.

    Best regards,
    Elric


  • 3.  RE: Monitoring Application on Endpoint

    Posted Dec 09, 2021 08:55 AM
    Hello Elric
    Very nice hearing from you. Thanks for the hint. I do get stuck however with that Agent Group. My machines of that range do have a unique machine name content. But the Agent Group configuration screen doesn't give me the option related to the name. Would that be the "Agent Host Domain" Option? I'm puzzled ...

    Best regards
    André



  • 4.  RE: Monitoring Application on Endpoint

    Posted Dec 09, 2021 09:14 AM
    I do not understand, for me it seem you did it with the always include these agents ?
    If you put something like VDI* and if your hostnames are VDR1234 it will match and the configuration will be used.

    Best regards,
    Elric


  • 5.  RE: Monitoring Application on Endpoint

    Posted Dec 09, 2021 09:25 AM
    Maybe I misunderstood the GUI and it is sufficient to just specify the "Always include these agent" and do nothing with the "Select Agent Attribute" drop down list ...


  • 6.  RE: Monitoring Application on Endpoint

    Posted Dec 10, 2021 02:46 AM
    Always include these agent is a placeholder for the Agent host name attribute.
    They choose to show it differently.

    Best regards,
    Elric


  • 7.  RE: Monitoring Application on Endpoint

    Posted Dec 10, 2021 03:01 AM
    Thanks Elrich, this explains it. 
    Best regards
    André


  • 8.  RE: Monitoring Application on Endpoint

    Trusted Advisor
    Posted Dec 09, 2021 01:40 PM
      |   view attached
    Andre,

    If you are trying to monitor a VDI, are you using Vmware or another virtual desktop host? If so, all you need to do is install the Agent on the VDI Host. It will then watch all of the Desktops on the VDI server. Look at page 27 of the requirements guide.. (Attached)

    This way any Desktop that is spun up on that Virtual HOST will be covered. This is the right way to segment and control what VDI's get what configuration.

    If you are trying to have a different configuration for different VDI's on the SAME Virtual Host/Server, it will be painful to test out and do. As you cannot uncheck some functionality on USB and Local Drive monitoring, since they are monitored through the VDI Server IO interfaces.

    Otherwise you can just list out all of the agents as part of the Agent Group (Always include these agents)


    ------------------------------
    Good Luck. - RP
    PLEASE MARKED SOLVED WHEN POSSIBLE
    ------------------------------

    Attachment(s)