Jump to content

Problem in Rogue Detection Sensor


Recommended Posts

Hi dear ESET Admins.

We find a strange  problem in V7 Rogue Detection Sensor, We want to know why all the find mac in rogue list is detected as ESMC Server Name !

As you can see in the attached screenshot 37 system is found but all of them is shown as Computer name  "Same name as Computer Name of ESMC Server"

in this situation we have not any "Add Computers" option in this list and when we right click in the list it is ESMC server right click. it means console Detect all the system as one computer.

What is the problem ?

Rogue Problem.png

Link to comment
Share on other sites

  • ESET Staff

Not sure which report is this, but I guess that "Computer Name" in this case is device where RogueDetectionSensor is installed, i.e. it is machine which made detection. Is actually RDSensor installed on the same machine as ESMC?

Link to comment
Share on other sites

11 hours ago, MartinK said:

Not sure which report is this, but I guess that "Computer Name" in this case is device where RogueDetectionSensor is installed, i.e. it is machine which made detection. Is actually RDSensor installed on the same machine as ESMC?

Yes , in This case Sq12R2 is the system that ESMC & RDSensor is installed.

We think that the report is wrong and they must use Report: Rogue Computers instead to have Add computer option.

Link to comment
Share on other sites

  • ESET Staff

Created report template is not the default report template. In the V7, we have added the option to filter rogue detection report by the source RD sensor. Therefore the "computer name column" is showing the name of the device. It would be beneficial, if they either drill down from the main dashboard, where a ratio between managed / known / rogue devices is shown, or use the actual "rogue computers" report, as found in the reports section.

Link to comment
Share on other sites

1 hour ago, MichalJ said:

Created report template is not the default report template. In the V7, we have added the option to filter rogue detection report by the source RD sensor. Therefore the "computer name column" is showing the name of the device. It would be beneficial, if they either drill down from the main dashboard, where a ratio between managed / known / rogue devices is shown, or use the actual "rogue computers" report, as found in the reports section.

Yes , That's it .

Best regards.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...