Using McAfee ePO integration in Analyst Workspace
Use the McAfee ePO integration to leverage the McAfee ePO capabilities on the SIR Analyst workspace.
始める前に
Role required: sn_si.admin
Before you use McAfee ePO integration on the Security Incident Response workspace, you must download it from the ServiceNow Store and configure it. For more information, see Set up your ServiceNow AI Platform instance for the McAfee ePO integration.
このタスクについて
You can use the McAfee ePO integration to make remediation actions on the endpoints in real time, use profiles to gather details about the host, and make specific queries or actions on the endpoint using the Security Incident Response workspace.
The McAfee ePO integration enables analysts to use the following McAfee ePO capabilities on the Security Incident Response Analyst workspace:
- Get Host Details
- Isolate Host
- Remove Isolation
- Run Additional Action(s) on Endpoint