Data Loss Prevention

 View Only

Symantec DLP- How to Filter and Export Endpoint Agents List 

Feb 20, 2012 06:26 AM

One of the integral part of Symantec DLP is it's agents which are deployed on the endpoint desktop and laptops. There are many administrative activities around those endpoint agents. One of the key requirement is to filter the agent based on their status and export as *.csv file. Then using MS Excel or Open Office or any office suite and work on those agents' status.

For example: You may be requested to provide the list of all version 11.1.1 agents to projects team, who can work on those and get those upgraded to ver 11.5. Another example could be that you need a list of all version 11.5 agents, which are in disconnected state.

Let's take a simple example of exporting all version 11.5 agents list.

Multiple filters can also be applied. We will see that also.

Login to DLP console, and go to System-->Agents-->Overview. See the image below for better understanding.

Then click on 'Advanced Filters & Summarization'. Click on 'Add Filters' in the right hand side of the screen. You can add more than one filter, as seen in the image below. Agents can be filtered on the basis of agent IP, agent version, agent status, connection status etc, as seen in the image below(drop down menu). Select 'agent version' for our example.

Once, in the first drop down, agent version is selected, second drop down will talk about the condition for filtering. This could include 'Contains Ignore Case', 'Does Not Contain Ignore Case', 'Matches Exactly' etc. See the image below. Let's select 'Contain Ignore Case' for our example. In the below image, also see the red cross mark. This is used for removing that filter (see our 2nd pic, where we have added 3 filters).

Then in the 3rd text box (right hand side), write 11.5. This means that we want to apply a filter, which will check for agent version which contains 11.5 (ignoring case, however this is irrelevant here. This can be used when we apply filter on hostname, for example). See the image below.

On the right hand side of the screen, you can see apply button. Once you click on apply button, a list of all 11.5 version agents will be displayed. By default, first 50 entry will be displayed. You can click on 'show all' to see agents. Then, once you show all, select all by clicking in the box in the bottom left hand side of the image below. This will select all. Then you can click on Export--Export All: CSV.

Then you can save the file on your local computer, or you can open directly.

This *.csv can be used to further analyze, distribute for further action or for reporting.

I hope this is quite comprehensive and covers everything with respect to exporting agents list. I hope this will help all.

Statistics
0 Favorited
4 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Mar 12, 2014 06:23 AM

Nice article dear..Thumbs up for this grt article.

Mar 14, 2012 05:06 AM

yes Ashok sir,

We can see the status of agents whether they are working or in dead status.

Regards

Kishorilal

Mar 06, 2012 04:36 AM

Hi AR,

 

How do we find out whether DLP agent is properly installed or not? Is there a way to cross check it just after it has been installed and on the same system i.e. endpoint.

Feb 22, 2012 03:39 AM

Thanks Steverd, for your suggestion...I have corrected the same in the article.

Feb 21, 2012 10:56 PM

One correction to the content: DLP does not support deploying agents on tablets. The DLP for Tablets solution is agent-less.

Related Entries and Links

No Related Resource entered.