Host Protection for Windows agent is not generating network events

Technote (troubleshooting)


Problem(Abstract)

The IBM Host Protection may not be creating network-based events, but is creating OS audit events.

Resolving the problem

The Host Protection for Windows agent uses an inline driver that connects to the Base Filtering module. If the service that controls this is disabled or not running, network traffic will bypass the agent's network driver. The agent will continue to function and report audit events, but it will not see network traffic.
Verify that the following service is running in Windows Services:

Base Filtering Engine



If the above information does not resolve your issue, please contact IBM Security Systems Customer Support.

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

IBM Security Host Protection
Proventia Server

Software version:

2.2.2

Operating system(s):

Windows

Reference #:

1621070

Modified date:

2013-01-18

Translate my page

Machine Translation

Content navigation