OK indicates that the agent is installed and has communicated (hearbeated) with Armor.
Location
For Armor Enterprise Cloud, this column will display name of the Armor virtual site.
For Armor Anywhere, this column will display the name of the public cloud provider.
Ticket
This column displays the support ticket that troubleshoots the Protection issue. A Protection issue will automatically generate a support ticket.
Health Rules
Health Rules calculates the status of several managed services provided or orchestrated by Armor. The status of these checks roll into AMP's Protection and help guide our support and remediation efforts.
The health rules are grouped under each Rule Family.
Types of Rule Family
Armor Agent
File Logging
FIM
IDS
Log Collector
Malware Protection
OS Monitoring
Vulnerability Scanning
Windows Event Logging
Rule Family
Rule
Description
Service
Frequency
Armor Agent
HasRecentHeartbeat
If latest CORE heartbeat is > 4 hours
Armor Agent
Hourly
Armor Agent
HasCorrectVersion
If CORE Agent is not running latest version
Armor Agent
Hourly
File Logging
HasCorrectVersion
If Filebeat is not running the latest version
Filebeat
Hourly
File Logging
HasRecentLogs
If last received log for that CoreinstanceId is > 4 hours from ELK
Filebeat
Hourly
File Logging
IsInstalled
If Filebeat agent is not installed
Filebeat
Hourly
Window Event Logging
HasCorrectVersion
If Winlogbeat is not running the latest version
Winlogbeat
Hourly
Window Event Logging
HasRecentLogs
if last received log for that CoreinstanceId is > 4 hours from ELK
Winlogbeat
Hourly
Window Event Logging
IsInstalled
If Winlogbeat agent is not installed
Winlogbeat
Hourly
FIM
HasRecentHeartbeat
If latest Trend heartbeat is > 4 hours
Trend
Hourly
FIM
IsPluginPresent
If FIM is "On, matching module plug-in not found"
Example : FIM On but Module Not Found
Trend
Hourly
FIM
IsRealtimeOrHasRules
If FIM is not "On, Realtime", or "On" with > 0 rules (
Example: FIM On but No Policy
Trend
Hourly
FIM
ModuleIsOn
If FIM is not "On"
Trend
Hourly
IDS
HasRecentHeartbeat
if latest Trend heartbeat is > 4 hours
Trend
Hourly
IDS
HasRules
If IDS is "On" and has > 0 rules
Example: IDS installed but no rules
Trend
Hourly
IDS
IsOnTapMode
If IDS is "On" and has tap mode on
Trend
Hourly
IDS
ModuleIsOn
If IDS is not "On"
Trend
Hourly
Malware Protection
HasAgentFailed
if Anti-Malware update failed
Trend
Hourly
Malware Protection
HasRecentHeartbeat
If latest Trend heartbeat is > 4 hours old
Trend
Hourly
Malware Protection
IsRebootRequired
if Anti-Malware status is "Computer reboot required"
Trend
Hourly
Malware Protection
ModuleIsOn
If Anti-Malware is not "On"
Trend
Hourly
Malware Protection
ModuleOnPluginNotFound
If Anti-Malware is "On, matching module plug-in not found"
Trend
Hourly
OS Monitoring
HasCorrectVersion
If Panopta is not running the latest version
Panopta
Hourly
OS Monitoring
IsInstalled
If Panopta is not Installed
Panopta
Hourly
Vulnerability Scanning
InMostRecentScan
If IR Agent did not scan in previous scan period
IR Agent
10 PM UTC once in Sunday
Vulnerability Scanning
IsInstalled
If IR Agent is not installed
IR Agent
10 PM UTC once in Sunday
Log Collector
HasDelayedLogs
if Events from this Log Collector are averaging longer than 1 hour to be received
Logstash
Hourly
Log Collector
HasRecentLogs
if events from this Log Collector have been received > 80%
Logstash
Hourly
Improve your Protection Score
You can use the information below to troubleshoot the issues displayed in the Protection screen.
Armor recommends that you troubleshoot these issues to:
Improve your Protection scores
Improve your overall health scores
Increase the overall security of your environment
Review each step to troubleshoot your problem. If the first step does not resolve the issue, then continue to the second step until the issue has been resolved. As always, you can send a support ticket.
To learn how to send a support ticket, see Armor Support.
Logging
Issue: The filebeat logging agent is not installed.
Description
Command
Extra information
Windows
Configurations are stored in the winlogbeat and filebeat directory within C:\.armor\opt\
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
Linux
Verify a 200 response
CODE
/opt/ds_agent/dsa_control -m
Issue: Malware Protection is not installed or configured
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
Linux
Verify a 200 response
CODE
/opt/ds_agent/dsa_control -m
Issue: FIM is installed but has not been configured
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
Linux
Verify a 200 response
CODE
/opt/ds_agent/dsa_control -m
Intrusion Detection System (IDS)
Issue: IDS has not provided a heartbeat in the past 4 hours
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
Linux
Verify a 200 response
CODE
/opt/ds_agent/dsa_control -m
Issue: IDS is installed but has not been configured
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
PS C:\Users\Administrator> & "C:\Program Files\Trend Micro\Deep Security Agent\dsa_control.cmd" -m
HTTP Status: 200 - OK
Response:
Manager contact has been scheduled to occur in the next few seconds.
Linux
CODE
/opt/ds_agent/dsa_control -m
Vulnerability Scanning
To remediate Vulnerability Scanning issues, please refer to this documentation.
Export Protection Screen Data
In the Armor Management Portal (AMP), in the left-side navigation, click Security.
Click Protection.
(Optional) Use the search bar to customize the data displayed.
Below the table, click CSV. You have the option to export all the data (All) or only the data that appears on the current screen (Current Set).
Column
Description
Column
Description
Asset Name
This column display the name of the virtual machine (or instance).
Location
This column displays the data center location for for the virtual machine (or instance).
Service
For Armor Enterprise Cloud, the Protection scores focuses on the following services:
Malware Protection
FIM
Filebeat (for Linux)
Winlogbeat (for Windows)
For Armor Anywhere, the Protection scores focuses on the following services:
Malware Protection
FIM
IDS
Filebeat (for Linux)
Winlogbeat (for Windows)
Vulnerability Scanning
Status
This column displays the security status of the virtual machine (or instance), which can be:
Warning
Needs Attention
OK
Message
This column displays a brief message to explain the reason for the Warning or Needs Attention status.
JavaScript errors detected
Please note, these errors can depend on your browser setup.
If this problem persists, please contact our support.