Live Monitoring: OnGuard Activity

The OnGuard Activity page shows the real-time status of all endpoints that have Policy Manager OnGuard. This page also presents configuration tools to bounce an endpoint, restart a session, and send unicast or broadcast messages to all endpoints running the OnGuard agent.

To access the OnGuard Activity page:

1. Navigate to Monitoring > Live Monitoring > OnGuard Activity. The OnGuard Activity page opens:

Figure 1  OnGuard Activity Page

Filtering by MAC Address

Policy Manager allows you to search for a MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address in any of the following formats:

112233AABBCC

11:22:33:aa:bb:cc

11-22-33-AA-BB-CC

1111-2222-3333

1111.2222.3333

About OnGuard Agent Type

The Type column in the OnGuard Activity page indicates Agent Type: Persistent Agent, Agentless OnGuard, etc. This column shows the Agent Type of the last request. For details on the Host:AgentType attribute, see Table 2: Service Rule > Web-Based Health Check Only Host Attributes.

OnGuard Activity Action Buttons

The following table describes the action buttons on the OnGuard Activity page:

Table 1: OnGuard Activity Action Buttons

Action Button

Description

Send Message

Click Send Message to send a message to the selected endpoints. For details, see Sending a Message to Selected Endpoints.

Send Notification

Click Send Notification to apply the Bounce or Restart Session notification options to one or more endpoints that you selected in the OnGuard Activity list. For details, see Broadcasting Notifications to OnGuard Agents.

OnGuard Activity Status Icons

The OnGuard Activity Status column shows status of OnGuard Agents: Persistent, Agentless, and Native Dissolvable Agent.

Agentless OnGuard Launch Status

When Agentless OnGuard is launched, it shows the status as one of the following:

Success: Agentless OnGuard was launched successfully.

Failure: Policy Manager server failed to launch Agentless OnGuard.

Agent Online/Offline Status

Online: Persistent or Agentless OnGuard is connected and is sending Keep-alive messages.

Offline: Persistent or Agentless OnGuard is not connected to the network.

 

The status for Native Dissolvable Agent is always Offline because the Native Dissolvable Agent shuts down after performing health checks and does not send Keep-alive messages to the Policy Manager server.

The following table describes the status icons that are displayed in the Status column of the OnGuard Activity page:

Table 2: OnGuard Activity Status Icons

OnGuard Icon

Status

Description

Failure

Failed to launch Agentless OnGuard on this client.

Success

Successfully launched Agentless OnGuard on this client.

Online

OnGuard Agent (Persistent or Agentless) is currently online or connected to a Policy Manager server.

Offline

OnGuard Agent (Persistent or Agentless) is currently offline or not connected to a Policy Manager server.

Agentless OnGuard Log

The Agentless OnGuard Log provides a log of all Agentless OnGuard activity for an endpoint.

To access the Agentless OnGuard Log:

1. From the OnGuard Activity page, click the row for the desired endpoint.

The Agent and Endpoint Details page opens.

2. Select the Agentless OnGuard Log tab.

Figure 2  Agentless OnGuard Log

Table 3: Agentless OnGuard Log Description

Parameter

Action/Description

Updated At

Indicates the time when a request to launch Agentless OnGuard was processed by the Policy Manager server.

Status

Indicates whether launching Agentless OnGuard was a success or it failed.

Policy Manager Server

IP address of Policy Manager server that processed the request to launch Agentless OnGuard.

Description

Shows detailed output of launching Agentless OnGuard.

For a Failure status, it describes why the Policy Manager server was not able to launch Agentless OnGuard.

Viewing Authentication Records

From the OnGuard Activity page, you can view the authentication records for the online devices that are listed.To view the authentication records for a device that is online, click the View button on the pertinent row. The Endpoint Authentication Details page opens.

Figure 3  Viewing an Endpoint's Authentication Records