Remote Monitoring & Management Help

Antivirus Update Check

The Antivirus Update Checks monitors the client's anti-virus program's pattern file to determine whether it is in sync with the vendor's latest published version, we receive a feed of this information on every vendor update, if a discrepancy exists the Check fails.

Our users use this to...

Anti-Virus Checks typically fall into the 'every-unit-items' that our users deploy to cut their costs. The cost of the Antivirus Update Check far outweighs the cost of engineering time spent recovering from a successful virus attack and our users usually use this as a 'baseline' check and deploy it across their base so as to avoid that engineering cost.

Use Configure Antivirus Alert suppression to select the number of consecutive failures before the Antivirus Update Check is reported as failed.

Antivirus Update Check URL from Agent 10.6.0

Windows Monitoring Agent 10.6.0 introduced a change to the definition comparison process for the Antivirus Update Check.

From this release, the Agent queries a CloudFront address over a secure connection to retrieve the information required to determine whether the installed Antivirus prodigious definitions are within the threshold or out-of-date.

To ensure the Agent can retrieve this information from CloudFront, we would suggest that you whitelist the below address in your firewall or web-filtering software.

https://dg5bj97jvb67q.cloudfront.net

Amazon's CloudFront Global Edge Network was utilized for this service, as it provides a consistent, high availability platform accessible from multiple geographically located download addresses.

This CloudFront address is strictly used to query and retrieve the Antivirus Update information, it is not used in any other capacity to receive or host data.

Dashboard Check configuration

Add

  1. Select the device in the north pane of the Dashboard
  2. Go to the Checks tab
  3. Click Add Check
  4. Choose Add DSC > Backup Check
    1. Select the Supported anti-virus product from the drop-down

    2. Choose the Days to run (we recommend running the check every day)
  5. To run an Automated Task when the Check fails choose Assign a Task after creating the Check
  6. OK to save and apply
  7. Where Assign a Task after creating the Check is selected:
    1. Select the script
    2. Click Next to configure
  8. Enter the Command Line parameters (if required)
  9. Set a Script timeout in the range 1 - 3600 seconds (default 120 seconds)
  10. Click Finish to save and apply

Edit

  1. Select the device in the north pane of the Dashboard
  2. Go to the Checks tab
  3. Select the target Backup Check
  4. From the Check drop-down
  5. Click Edit Check (also available from the Check's right-click menu)
  6. Configure the settings
  7. Click OK to save and apply

Delete

  1. Select the device in the north pane of the Dashboard
  2. Go to the Checks tab
  3. Select the target Backup Check
  4. From the Check drop-down
  5. Click Delete Check (also available from the Check's right-click menu)
  6. Enter the password you have logged into the Dashboard under to confirm removal
  7. Click OK to delete

The Antivirus Update Check from Windows Monitoring Agent 10 utilizes the legacy Check processor and although the Check will run at the same schedule as the other Daily Safety Checks, it will report back a different time in the Date/Time column