Nonconform
Endpoints with unresolved threats and those that encountered threat mitigation issues are considered nonconforming. Threat Mitigator reports these endpoints to TMSP.
To view nonconforming endpoints:
Customers
Click View under the Nonconforming Endpoints column.
Select from the following tabs:
Nonconforming Endpoints: Displays the IP addresses of nonconforming endpoints
Information in the Nonconforming Endpoints table |
Column Title |
Information |
IP Address |
Shows the IP addresses and host names of nonconforming endpoints. Host names are enclosed in parentheses. Filter the IP addresses that display by selecting one of the following items in the dropdown box below the IP Address column:
|
<Second to sixth column> |
The column titles indicate the dates of the last five days and the total number of threat events detected on each date. For example, a column with the title 2010-06-30 (23) means that there are a total of 23 threat events detected on all nonconforming endpoints on June 30, 2010. Each cell shows the number of threat events detected on an endpoint for a particular date. |
Last Threat Sample Received |
Shows the date and time forensic data was received from the endpoint N/A displays if there is no forensic data in TMSP for the particular endpoint, which can happen for many reasons. For example, an agent may have collected data but encountered problems uploading the data to Threat Mitigator. |
Last Pattern Deployed |
Shows the date and time Threat Mitigator downloaded a custom pattern from TMSP N/A displays if Threat Mitigator has not received any pattern from TMSP. |
Yesterday’s Nonconforming Endpoints: Provides a graph that shows threat events logged from nonconforming endpoints at various hours of the previous day
Yesterday’s Threat Mitigation Issues: Displays the IP addresses of endpoints with threat mitigation issues
Information in the Yesterday’s Threat Mitigation Issues table |
Column Title |
Information |
IP Address |
Shows the IP addresses and host names of endpoints that encountered mitigation issues. Host names are enclosed in parentheses. Filter the IP addresses that display by selecting one of the following items in the dropdown box below the IP Address column:
|
Agent Initialization Issue |
Indicates endpoints that encountered errors initializing Threat Management Agent |
Internal Error |
Indicates endpoints that encountered agent component errors |
Pattern Not Found |
Indicates endpoints that do not have a pattern required for threat mitigation |
Configuration Error |
Indicates endpoints with corrupted threat mitigation components or files |
See also: