McAfee ePO Endpoint Connectivity Diagnostics Playbook Deprecated Hidden

Deprecated. Use "McAfee ePO Endpoint Connectivity Diagnostics Playbook V2" playbook instead. Perform a check on ePO endpoints to see if any endpoints are unmanaged or lost connectivity with ePO and take steps to return to valid state.

Deprecated Content (Deprecated) · 12 tasks · 0 inputs · 0 outputs

Details

IDplaybook13
From Version5.0.0
Tasks12

Commands used

servicenow-incident-create

Flowchart

No Yes Yes no start_task start_task Are any endpoints in ePO listed as unmanaged? Are any endpoints in ePO ... Check if unmanaged endpoints are in special excluded list. Check if unmanaged endpoi... Open ServiceNow ticket for admin to install agents - servicenow-incident-create Open ServiceNow ticket fo... servicenow-incident-create Check if there are agents which haven't communicated with ePO in the past 3 days Check if there are agents... CloseInvestigation - CloseInvestigation CloseInvestigation CloseInvestigation Check connectivity for each endpoint using ping - Ping Check connectivity for ea... Ping Remotely check that McAfee Agent is installed and running Remotely check that McAfe... Remotely execute cmdagent commandline utility to force communication with ePO Remotely execute cmdagent... Retrieve McAfee Agent logs from non-communicating endpoints Retrieve McAfee Agent log... Store list of unmanaged endpoints to context key epoUnmanagedEndpoint - commentsToContext Store list of unmanaged e... commentsToContext Store non-communicating endpoints to context key epoNonCommunicatingEndpoint - commentsToContext Store non-communicating e... commentsToContext
id: playbook13
version: -1
system: true
fromversion: 5.0.0
name: McAfee ePO Endpoint Connectivity Diagnostics Playbook
description: Deprecated. Use "McAfee ePO Endpoint Connectivity Diagnostics Playbook V2" playbook instead. Perform a check on ePO endpoints to see if any endpoints are unmanaged or lost connectivity with ePO and take steps to return to valid state.
starttaskid: "0"
hidden: true
tasks:
  "0":
    id: "0"
    taskid: 0e3fe5d5-d93f-4ce9-8b62-685427fb9e5a
    type: start
    task:
      id: 0e3fe5d5-d93f-4ce9-8b62-685427fb9e5a
      version: -1
      description: ""
      name: start_task
      type: start
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "1"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 416,
          "y": -227
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "1":
    id: "1"
    taskid: 9c37c208-6466-4564-87db-2ebcdf47c9ad
    type: condition
    task:
      id: 9c37c208-6466-4564-87db-2ebcdf47c9ad
      version: -1
      name: 'Are any endpoints in ePO listed as unmanaged? '
      description: Place the list of non-communicating endpoints in incident label epoUnmanagedEndpoints
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "4"
      "Yes":
      - "2"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 416,
          "y": -90
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "2":
    id: "2"
    taskid: 956874f3-ed9f-4e74-850b-4e98a76e2ce7
    type: regular
    task:
      id: 956874f3-ed9f-4e74-850b-4e98a76e2ce7
      version: -1
      name: Check if unmanaged endpoints are in special excluded list.
      description: |-
        Most organizations have some excluded servers, either legacy OS, or being managed by a different security solution, etc.
        Usually this list is managed in Active Directory and this task is accomplished by checking whether any computers in the unmanaged list are a member of this group.

        Type in the comments the system names that need to be handled - comma separated
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "10"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 94
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "3":
    id: "3"
    taskid: a6a568b4-7902-40da-8d7d-bb87db62debc
    type: regular
    task:
      id: a6a568b4-7902-40da-8d7d-bb87db62debc
      version: -1
      description: ""
      name: Open ServiceNow ticket for admin to install agents
      script: ServiceNow|||servicenow-incident-create
      type: regular
      iscommand: true
      brand: ServiceNow
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      active: {}
      activity_due: {}
      additional_assignee_list: {}
      approval: {}
      approval_history: {}
      approval_set: {}
      assigned_to: {}
      assignment_group: {}
      assignmentgroup: {}
      business_duration: {}
      business_service: {}
      business_stc: {}
      calendar_duration: {}
      caller_id: {}
      category:
        simple: Software
      caused_by: {}
      close_code: {}
      close_notes: {}
      closed_at: {}
      closed_by: {}
      cmdb_ci: {}
      comments:
        simple: ${epoUnmanagedEndpoint}
      comments_and_work_notes: {}
      company: {}
      contact_type: {}
      correlation_display: {}
      correlation_id: {}
      delivery_plan: {}
      description: {}
      display: {}
      due_date: {}
      escalation: {}
      expected_start: {}
      follow_up: {}
      group_list: {}
      impact: {}
      incident_state: {}
      knowledge: {}
      location: {}
      made_sla: {}
      notify: {}
      number: {}
      order: {}
      parent: {}
      parent_incident: {}
      priority: {}
      problem_id: {}
      reassignment_count: {}
      reopen_count: {}
      resolved_at: {}
      resolved_by: {}
      rfc: {}
      severity: {}
      short_description:
        simple: Unmanaged endpoints - need to install McAfee Agent
      shortdescription:
        simple: Unmanaged EP
      sla_due: {}
      subcategory:
        simple: Antivirus
      sys_updated_by: {}
      sys_updated_on: {}
      urgency: {}
      user_input: {}
      watch_list: {}
      work_end: {}
      work_notes: {}
      work_notes_list: {}
      work_start: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 428
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "4":
    id: "4"
    taskid: 1d99f9b9-166a-4248-84f6-b90c15951e33
    type: condition
    task:
      id: 1d99f9b9-166a-4248-84f6-b90c15951e33
      version: -1
      name: Check if there are agents which haven't communicated with ePO in the past 3 days
      description: Type in comments the system names that need to be handled - comma separated
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "Yes":
      - "11"
      "no":
      - "5"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 416,
          "y": 591
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "5":
    id: "5"
    taskid: f35617e9-0a55-4967-8a2e-1c878e4711a0
    type: regular
    task:
      id: f35617e9-0a55-4967-8a2e-1c878e4711a0
      version: -1
      description: ""
      name: CloseInvestigation
      scriptName: CloseInvestigation
      iscommand: false
      brand: ""
    scriptarguments:
      notes: {}
      reason: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 116,
          "y": 754
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "6":
    id: "6"
    taskid: 4a32bb9b-8d01-48f5-8685-c754b5067c09
    type: regular
    task:
      id: 4a32bb9b-8d01-48f5-8685-c754b5067c09
      version: -1
      description: ""
      name: Check connectivity for each endpoint using ping
      scriptName: Ping
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "7"
    scriptarguments:
      address:
        simple: ${epoNonCommunicatingEndpoint}
      contextKey: {}
      verbose: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 935
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "7":
    id: "7"
    taskid: b5a87844-2303-4da8-8b3f-9824047aa547
    type: regular
    task:
      id: b5a87844-2303-4da8-8b3f-9824047aa547
      version: -1
      description: ""
      name: Remotely check that McAfee Agent is installed and running
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 1124
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "8":
    id: "8"
    taskid: 2c6c6764-94f8-4777-836b-649ef7b51b98
    type: regular
    task:
      id: 2c6c6764-94f8-4777-836b-649ef7b51b98
      version: -1
      description: ""
      name: Remotely execute cmdagent commandline utility to force communication with ePO
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "9"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 1311
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "9":
    id: "9"
    taskid: 70cbf053-e249-48eb-823e-10c903391df5
    type: regular
    task:
      id: 70cbf053-e249-48eb-823e-10c903391df5
      version: -1
      description: ""
      name: Retrieve McAfee Agent logs from non-communicating endpoints
      type: regular
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 1498
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "10":
    id: "10"
    taskid: b5f717be-a4a8-4ba2-86ca-6f6e4024236c
    type: regular
    task:
      id: b5f717be-a4a8-4ba2-86ca-6f6e4024236c
      version: -1
      name: Store list of unmanaged endpoints to context key epoUnmanagedEndpoint
      description: Takes the comments of a given entry ID and stores them in the incident context, under a provided context key. For accessing the last executed task's comments, provide ${lastCompletedTaskEntries.[0]} as the value for the entryId input parameter.
      scriptName: commentsToContext
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      contextKey:
        simple: epoUnmanagedEndpoint
      entryId:
        simple: ${lastCompletedTaskEntries.[0]}
      listSeperator:
        simple: ','
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 271
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "11":
    id: "11"
    taskid: 3da5d5ef-6d6a-4099-8d83-d5a33d6ef515
    type: regular
    task:
      id: 3da5d5ef-6d6a-4099-8d83-d5a33d6ef515
      version: -1
      name: Store non-communicating endpoints to context key epoNonCommunicatingEndpoint
      description: Takes the comments of a given entry ID and stores them in the incident context, under a provided context key. For accessing the last executed task's comments, provide ${lastCompletedTaskEntries.[0]} as the value for the entryId input parameter.
      scriptName: commentsToContext
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "6"
    scriptarguments:
      contextKey:
        simple: epoNonCommunicatingEndpoint
      entryId:
        simple: ${lastCompletedTaskEntries.[0]}
      extend-context: {}
      listSeperator:
        simple: ','
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 731,
          "y": 754
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 1820,
        "width": 995,
        "x": 116,
        "y": -227
      }
    }
  }
inputs: []
outputs: []
tests:
- No test
deprecated: true