Security command manual


















This website requires certain cookies to work and uses other cookies to help you have the best experience. By visiting this website, certain cookies have already been set, which you may delete and block. By closing this message or continuing to use our site, you agree to the use of cookies. Visit our updated privacy and cookie policy to learn more. This Website Uses Cookies By closing this message or continuing to use our site, you agree to our cookie policy. Learn More This website requires certain cookies to work and uses other cookies to help you have the best experience.

This is a Windows-only feature. You'll need Deep Security Manager for that. Used in conjunction with the -x option to specify the proxy's username and password, if the proxy requires authentication.

Separate the username and password by a colon :. For example,. To remove the username and password, type an empty string "". If you only want to update the proxy's password without changing the proxy's username, you can use the -u option without -x. No security policy is changed on the manager as a result of running this command. Used in conjunction with the -y option to specify the proxy's username and password, if the proxy requires authentication. If you only want to update the proxy's password without changing the proxy's username, you can use the -w option without -y.

For more information, see Connect to Deep Security Manager via proxy. For more information, see Connect to Deep Security Relays via proxy. Enabling agent-initiated activation AIA can prevent communication issues between the manager and agents, and simplify agent deployment when used with deployment scripts. For instructions on how to configure AIA and use deployments scripts to activate agents, see Activate and protect agents using agent-initiated activation and communication.

Like activation, the heartbeat command can also send settings to the manager during the connection. Sets the display name shown in parentheses next to the hostname on Computers. Maximum length characters. Sets the externalid value. This value can be used to uniquely identify an agent. Sets which group the computer belongs to on Computers. Maximum length characters per group name per hierarchy level. The group parameter can read or create a hierarchy of groups.

This parameter can only be used to add computers to standard groups under the main "Computers" root branch. It cannot be used to add computers to groups belonging to directories Microsoft Active Directory , VMware vCenters, or cloud provider accounts.

The policy name is a case-insensitive match to the policy list. If the policy is not found, no policy will be assigned. A policy assigned by an event-based task will override a policy assigned during agent-initiated activation.

Links the computer to a specific relay group. The relay group name is a case-insensitive match to existing relay group names. If the relay group is not found, the default relay group will be used. This does not affect relay groups assigned during event-based tasks. Use either this option or event-based tasks, not both. If using agent-initiated activation as a tenant, both tenantID and token are required. The tenantID and token can be obtained from the deployment script generation tool.

Learn more. To activate an agent from the command line, you need to know the tenant ID and password. You can get them from the deployment script. If you need to troubleshoot a Deep Security Agent issue, your support provider might ask you to create and send a diagnostic package from the computer. For more detailed instructions, see Create an agent diagnostic package via CLI on a protected computer.

So when Technical Support asks for a diagnostic package, you need to run the command directly on the agent computer. Authentication password used with the optional agent self-protection feature.

Required if you specified a password when enabling self-protection. For some query-commands, authentication can be bypassed directly, in such case, password is not required. Execute query-command against the agent.

The following commands are supported: "GetHostInfo" : to query which identity is returned to the manager during a heartbeat "GetAgentStatus" : to query which protection modules are enabled, the status of Anti-Malware or Integrity Monitoring scans in progress, and other miscellaneous information "GetComponentInfo" : to query version information of anti-malware patterns and engines "GetPluginVersion" : to query version information of the agent and protection modules.

Some actions require either a -tenantname parameter or a -tenantid parameter. If execution problems occur when you use the tenant name, try the command using the associated tenant ID.

Add an Azure endpoint to the allowed endpoint list. Limit the amount of time officers view video monitors. According to the report, the quality of attention by officers monitoring video feeds falls to unacceptable levels after about 20 minutes. To address this challenge, officers scheduled for the same shift should switch duties every two to four hours.

Limit the number of video monitors. As more monitors are added, detection rates decrease. For example, an officer viewing one monitor has an 85 percent detection rate, while an officer viewing nine monitors has a 53 percent detection rate.

Be mindful of monitor set-up. Camera images with the most activity and traffic should appear larger on a monitor than camera images with less activity. Design your center with ergonomics in mind. Lighting, furniture design and air temperature must be appropriate and comfortable so officers can concentrate on the tasks at hand.



0コメント

  • 1000 / 1000