Host Protection for Windows agent is not generating network events

Technote (FAQ)


Question

Why would IBM Host Protection for Windows not be creating network-based events, but is creating OS audit events?

Answer


The Host Protection for Windows agent uses an inline driver that connects to the Base Filtering module. If the service that controls this is disabled or not running, network traffic will bypass the agent's network driver. The agent will continue to function and report audit events, but it will not see network traffic.

Verify that the following service is running in Windows Services:

Base Filtering Engine



If the above information does not resolve your issue, please contact IBM Security Systems Customer Support.

Rate this page:

(0 users)Average rating

Document information


More support for:

IBM Security Host Protection
Proventia Server

Software version:

2.2.2

Operating system(s):

Windows

Reference #:

1621070

Modified date:

2013-01-18

Translate my page

Machine Translation

Content navigation