eG - Monitoring
 

Measures reported by VmgWinSecurityTest

Windows Security Center (WSC) is a comprehensive reporting tool that helps administrators establish and maintain a protective security layer around Windows VMs to monitor the physical machine's/VM's health state. The Windows Security Center also monitors third party security products such as firewall, antivirus, antimalware and antispyware, installed on the VM/physical machine. In order for the security products to be compliant with Windows and successfully report status to Action Center, these products should be registered with the security center. The security products communicate any subsequent status changes to the security center using private APIs. The security center, in turn, communicates these updates to Action Center, where they are finally displayed to the end user. With Windows Security Center, administrators can check whether any security product is installed and turned on, and if the definitions of the products are up to date and real-time protection is enabled. By continuously monitoring the Windows Security Center, administrators can instantly find out whether the security products are up-to-date or out dated, and the status of security products in real-time. This is what exactly the WinSecurityTest test does!

This test auto-discovers the security products installed on the Windsows VMs on the target host, and for each security product reports the current definition status and the current protection status. Using these details, administrators are alerted to the systems on which the automatic updates are outdated and virus protection turned off. By closely monitoring the status, administrators can take necessary actions before the end users become vulnerable to virus threats or malicious attacks.

Outputs of the test : One set of results for every security product:provider combination on each Windows VMs/physical desktops.

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
Definition_status Indicates the current status of this security product.   The values reported by this measure and its numeric equivalents are mentioned in the table below:

Measure Value Numeric Value
Unknown 20
Up to date 15
Out of date 10

Note:

By default, this measure reports the Measure Values listed in the table above to indicate the current state of this security product. The graph of this measure however, represents the status of a server using the numeric equivalents only.

Use the detailed diagnosis of this measure, to know about the name of Windows system on which the product is running, the file paths of product executables and the current status of the product.

Real_time_protect_status Indicates the real-time protection status of this security product.   The values reported by this measure and its numeric equivalents are mentioned in the table below:

Measure Value Numeric Value
Unknown 25
Snoozed 20
On 15
Expired 10
Off 0

Note:

By default, this measure reports the Measure Values listed in the table above to indicate the current protection status of this security product. The graph of this measure however, represents the status of a server using the numeric equivalents only.