2019-09-16 12:52 PM
Hello.
I would like to know, regarding McAfee ePO integration via ODBC for Netwitness, the answer to the next questions:
1. What are the specific SQL tables consulted by the Event Source configuration?.
2. Is there any reports, metrics or evidence showing what is the increase of consumption in the related SQL Database due the Netwitness ODBC integration?.
3. Regarding the polling interval (default 180 seconds), what is the minimum value that can be set?
Thanks in advance for the help.
Best regards.
Sergio
2019-11-14 12:26 AM
Hi Sergio Gonzales,
Table details available in Page 5 of McAfee ePolicy Orchestrator Event Source Configuration Guide
Run Rule for device.ip=<epOIP> to check traffic consumption for duration.
default polling interval 180 secs work good for all environments. If you need this to be adjusted, you can go lesser value. But, polling start once previous poll thread completes.