USM Anywhere™

Configuring the AlienApp for McAfee ePO

Role Availability Read-Only Analyst Manager

The AlienApp for McAfee ePO connects to the Microsoft SQL database within your McAfee ePolicy Orchestrator (ePO) to retrieve and ingest data for analysis in USM Anywhere. After USM Anywhere analyzes the first of these events, the McAfee ePO dashboard is available.

Requirements

To configure the AlienApp for McAfee ePO, you must add a scheduled job in USM Anywhere that collects data directly from the SQL database in your McAfee ePO. Before you do this, there is information about your database that is required to make the connection:

  • Hostname or IP address of the SQL database
  • Port number (usually 1433) that is open for the connection
  • The database name
  • Username and password used to log in to the SQL database

    Important: This is the Microsoft SQL Server account and not the Microsoft Windows user account. The AlienApp for McAfee ePO uses SQL Server authentication over Windows Authentication.

Creating a Scheduler Job for McAfee ePO

The AlienApp for McAfee ePO page provides easy access to define a new log collection job to retrieve your McAfee ePO event data. After you create the new job, you can make changes to the parameters for the scheduled job or review its history in the Scheduler page. See Managing Jobs in the Scheduler for more information about working with scheduled jobs.

To schedule a McAfee ePO job

  1. In USM Anywhere, go to Data Sources > AlienApps.
  2. Click the Available Apps tab.
  3. Search for the AlienApp, and then click the tile.
  4. Click the Scheduling tab.
  5. Enable an existing job or click New Job.

    Add a log collection job for the AlienApp

    This opens the Schedule New Job dialog box with the options defined for an AlienApp for McAfee ePO job.

  6. Enter the name and description for the job.

    The description is optional, but it is a best practice to provide this information so that others can easily understand what it does.

  7. Enter a name and description for the new job

  8. Enter the McAfee ePO database connection information:

    Enter the McAfee ePO database connection information

    • In the IP address field, enter the IP address of the ePO server SQL database.
    • In the Port number field, enter the port number on which the ePO server SQL database listens.
    • In the Database name field, enter the name of the ePO server SQL database.
    • In the Username and Password fields, enter the credentials you use to access the ePO server SQL database.
  9. In the Schedule section, specify when USM Anywhere runs the job:

    1. Select the increment as Minute, Hour, Day, Week, Month, or Year.
    2. Set the interval options for the increment.

      The selected increment determines the available options. For example, on a weekly increment you can select the days of the week to run the job.

      Set the schedule for the job to run each week

      Or on a monthly increment, you can specify a date or a day of the week that occurs within the month.

      Set the schedule for the job to run each month

    3. Set the Start time.

      This is the time that the job starts at the specified interval. It uses the time zone configured for your USM Anywhere instance (default is Coordinated Universal Time [UTC]).

  10. Click Save.

After the scheduled job runs, you should start seeing new events in USM Anywhere originating from the ePO server SQL database.