- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Each day I open the SmartEndpoint I found different totals of endpoint installed, sometimes it goes up and sometimes goes down.
What could be the reason for that, as I need to send a report to my CISO every week.
How does heartbeat work to check if a machine is alive?
So i would use the Activity Reports group that includes these endpoint and Endpoint Policy Server status reports:
• Endpoint Connectivity - Shows the last time each endpoint computer connected to the network.
• Endpoints with Not Running Blades - Shows the status of components for users and endpoint computers. You can use this report to see which components are running or not running.
• Protected by Endpoint Security - Shows if endpoint computers are protected by Endpoint Security.
You can sort by status:
• Unprotected Computers - Computers that do not have the Endpoint Agent installed.
• Unassociated Users - Users who were identified in the Directory scan but did not log on to a computer with Endpoint Security.
• Endpoint Installed - Computers that have the Endpoint Agent installed.
• Endpoint Policy Server Status - Shows Endpoint Policy Server status (Active or Not Active)
• Endpoint Connectivity by External Policy Server - Shows which Endpoint Policy Server each endpoint communicates with.
See Endpoint Security Administration Guide R80.30 p.34f for details.
Why did you ask this question in Developers > API / CLI Discussion and Samples ? I would rather use Endpoint Security Products instead !
Different totals of Endpoints installed is strange - connected / disconnected is the usual numbers game...
Thanks for the reply G_W_Albrecht, I didn't notice.
I will pay attention next time.
Well all of them were connected and suddenly the number of machine has changed in a time period of a week.
I had 2204 machine installed with SandBlast Endpoint and now more than 100 machines are missing.
Is there a funtionality were checkpoint detach a machine from smartendpoint if that machine does not respond to heartbeat like in symantec? I remember symatec had 90 days rule to detach a machine.
So i would use the Activity Reports group that includes these endpoint and Endpoint Policy Server status reports:
• Endpoint Connectivity - Shows the last time each endpoint computer connected to the network.
• Endpoints with Not Running Blades - Shows the status of components for users and endpoint computers. You can use this report to see which components are running or not running.
• Protected by Endpoint Security - Shows if endpoint computers are protected by Endpoint Security.
You can sort by status:
• Unprotected Computers - Computers that do not have the Endpoint Agent installed.
• Unassociated Users - Users who were identified in the Directory scan but did not log on to a computer with Endpoint Security.
• Endpoint Installed - Computers that have the Endpoint Agent installed.
• Endpoint Policy Server Status - Shows Endpoint Policy Server status (Active or Not Active)
• Endpoint Connectivity by External Policy Server - Shows which Endpoint Policy Server each endpoint communicates with.
See Endpoint Security Administration Guide R80.30 p.34f for details.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY