Host Protection for Windows agent is not generating network events

Technote (FAQ)


Question

Why would IBM Host Protection for Windows not be creating network-based events, but is creating OS audit events?

Answer


The Host Protection for Windows agent uses an inline driver that connects to the Base Filtering module. If the service that controls this is disabled or not running, network traffic will bypass the agent's network driver. The agent will continue to function and report audit events, but it will not see network traffic.

Verify that the following service is running in Windows Services:

Base Filtering Engine



IBM Host Protection Documentation IBM Infrastructure Security Forums IBM Security Support Channel on YouTube IBM Fix Central Fixes and Updates IBM Security License Key and Download Center Subscribe to My Notifications for Important Product Alerts IBM Security Contact Support

Document information


More support for:

IBM Security Host Protection
Proventia Server

Software version:

2.2.2

Operating system(s):

Windows

Reference #:

1621070

Modified date:

2013-01-18

Translate my page

Content navigation