กลุ่มเมนู Logs › Endpoint Management บันทึกผลของการควบคุมที่ทำงานบนเครื่อง Endpoint ผ่าน Omnipoint Secure Client โดยแบ่ง Log เป็น 3 ส่วน คือ Peripheral Control (อุปกรณ์ต่อพ่วง เช่น Removable Storage), Port Control (การเชื่อมต่อเข้ามายังพอร์ตของเครื่อง) และ Software Control (การติดตั้งและการรันโปรแกรม) ผู้ดูแลระบบใช้ Log เหล่านี้ยืนยันว่า Policy ทำงานกับเครื่องจริง ตรวจย้อนหลังว่าอุปกรณ์ การเชื่อมต่อ หรือโปรแกรมใดถูก Block และหาข้อมูลเมื่อผู้ใช้แจ้งว่าใช้งานไม่ได้
สารบัญ
Log แต่ละส่วนมาจาก Policy ใด
| Log | ตำแหน่งในเมนู Logs | Policy ที่สร้าง Log | OS ที่รองรับ (ตามหน้าตั้งค่า Policy) |
|---|---|---|---|
| Peripheral Control | Logs › Endpoint Management › Endpoint Control › แท็บ Peripheral Control | Platform Management › Endpoints › Endpoint Control › Peripheral Control | Windows และ macOS |
| Port Control | Logs › Endpoint Management › Endpoint Control › แท็บ Port Control | Platform Management › Endpoints › Endpoint Control › Port Control | Windows |
| Software Control | Logs › Endpoint Management › Software Control | Platform Management › Endpoints › Software Control (Installation Control และ Execution Control) | Windows |
ทุกหน้าใช้รูปแบบเดียวกับหน้า Log อื่น คือเลือกช่วงเวลา (Today, Last 7 days, Last 30 days หรือ Custom) กรองด้วยช่อง Select filters and press Enter เลือกคอลัมน์ด้วยไอคอน ⋯ และ Export ข้อมูลออกได้
Peripheral Control
ไปที่ Logs › Endpoint Management › Endpoint Control แล้วเลือกแท็บ Peripheral Control
แท็บนี้บันทึกเหตุการณ์ของอุปกรณ์ต่อพ่วงตาม Peripheral Control Policy เช่น การเสียบหรือถอด Removable Storage และการทำงานกับไฟล์บนอุปกรณ์
คอลัมน์ได้แก่ Time, Username, Display Name, Asset Type, Department, Location, Source IP, Description, File Name, File Size, Source Path, Action และ Status หัวข้อกรองได้แก่ Keyword, Status, Asset Type, User/Department, Location และ Action
สำหรับการ Audit ไฟล์ที่คัดลอกออกไปยังอุปกรณ์ภายนอกตาม Policy ของ Data Loss Analysis ดูได้ที่ Logs › Critical Feature Logs › File Audit › External Devices
Port Control
Port Control ควบคุมการเชื่อมต่อที่เข้ามายังพอร์ตของเครื่อง Endpoint จาก Remote IP ที่กำหนดไว้ใน Policy (เลือกจาก IP Address Object ใน Objects › IP Addresses) เช่น ป้องกันไม่ให้เครื่องอื่นเปิด Remote Desktop หรือ File Sharing เข้ามายังเครื่องของพนักงาน ทุกครั้งที่ Policy Block การเชื่อมต่อ ระบบบันทึกเป็นหนึ่งแถวในแท็บนี้
ไปที่ Logs › Endpoint Management › Endpoint Control แล้วเลือกแท็บ Port Control
คอลัมน์ได้แก่ Time, Username, Display Name, Department, Endpoint Name, MAC Address, Private IP, Endpoint Type, Location, Protocol Type, Port, Remote IP และ Action เช่น Block connection หัวข้อกรองได้แก่ Endpoint Name, MAC Address, Private IP, Remote IP, Port, User/Department, Location, Protocol Type และ Action
-
อ่านแต่ละแถวดังนี้
- Username / Endpoint Name / Private IP: เครื่องที่ถูกเชื่อมต่อเข้ามา (เครื่องที่ Policy ป้องกัน)
- Remote IP: เครื่องต้นทางที่พยายามเชื่อมต่อเข้ามา
- Protocol Type / Port: พอร์ตปลายทางบนเครื่องที่ถูกป้องกัน เช่น TCP 3389 สำหรับ Remote Desktop
- Action: ผลที่ Policy ทำ เช่น Block connection
ตัวอย่าง: Policy ตั้ง Block connection สำหรับ TCP 3389 จาก Remote IP ของเครื่องในสำนักงาน เมื่อเครื่องเหล่านั้นพยายามเปิด Remote Desktop มายังเครื่องของพนักงาน ผู้ใช้ปลายทางจะเชื่อมต่อไม่ได้ และแท็บ Port Control แสดงแถวของเครื่องพนักงานพร้อม Remote IP ของเครื่องต้นทาง Port 3389 และ Action Block connection การเชื่อมต่อที่เครื่องพนักงานเริ่มออกไปเองไม่อยู่ในขอบเขตของ Port Control ถ้ายังไม่เห็นแถวล่าสุด ให้รอสักครู่แล้วกด Refresh
Software Control
ไปที่ Logs › Endpoint Management › Software Control หน้านี้เปิดที่ช่วง Last 7 days
ตารางมีคอลัมน์ Time, Username, Display Name, Department, Endpoint Name, MAC Address, Private IP, Software Name, Control Policy (ชื่อ Policy ที่ทำงาน) และ Action เช่น Block execution
หัวข้อกรองมีให้เลือกหลายแบบ เช่น Keyword, Endpoint Name, Software Name, Control Policy, User/Department, Action, Execution Process Name, Original File Name, Product Name และ App Signature
กด Details เพื่อดูผลการทำงานของ Policy (Policy Execution Results) ข้อมูลของโปรแกรม เช่น Product Name, Execution Process Name และ App Signature ที่ใช้ระบุโปรแกรม และข้อมูลผู้ใช้
ข้อมูลใน Details เช่น Execution Process Name และ App Signature ช่วยตรวจว่าระบบระบุโปรแกรมได้ตรงกับที่ตั้งใจหรือไม่ ถ้าโปรแกรมที่ต้องการควบคุมไม่อยู่ใน Predefined Desktop Apps ให้เพิ่มเป็น Custom Desktop App ใน Objects › Desktop Apps
ไม่พบ Log ที่คาดไว้
- Policy อยู่ในสถานะ Enabled และ Applicable Scope ครอบคลุมผู้ใช้หรือเครื่องนั้น
- เครื่องออนไลน์ และ Client อยู่ในสถานะปกติ ตรวจได้ที่ Endpoints › Endpoint Assets (คอลัมน์ Endpoint Status และ Client Component Status)
- OS ของเครื่องอยู่ในกลุ่มที่ Policy นั้นรองรับตามตารางด้านบน
- สำหรับ Port Control ให้ตรวจว่าทดสอบด้วยการเชื่อมต่อจากเครื่องอื่นเข้ามายังเครื่องที่อยู่ใน Applicable Scope และ Remote IP ของเครื่องต้นทางอยู่ใน IP Address Object ที่เลือกไว้
- ขยายช่วงเวลาให้ครอบคลุมเวลาที่เกิดเหตุการณ์ และกรองด้วย Endpoint Name หรือ User/Department ของเครื่องนั้น
Log ในกลุ่มนี้มีข้อมูลที่ระบุตัวผู้ใช้และเครื่องได้ (ชื่อผู้ใช้ ชื่อเครื่อง MAC Address และชื่อไฟล์) ควรให้สิทธิ์เข้าดูเฉพาะผู้ดูแลระบบที่ได้รับอนุญาต (กำหนดผ่าน Role ใน Admin Management) และใช้งานตามนโยบายความเป็นส่วนตัวขององค์กร หากต้องเก็บ Log ระยะยาว ให้ส่งต่อไปยัง Syslog Server ขององค์กรด้วย Syslog Forwarding
ข้อคิดเห็น
0 ข้อคิดเห็น
โปรด ลงชื่อเข้าใช้ เพื่อแสดงข้อคิดเห็น