How to automate ESET Security Management Center

By using the techniques shown in the example below, you can automate a variety of actions, from product and OS updates, scanning, and automatic activations of newly added products with preselected licenses, to solving sophisticated incidents.

validation-status-icon-error WARNING

Only attempt the techniques shown below on client computers that do not have third-party security software or ESET security software from the home segment (e.g. ESET Smart Security) installed. Installing ESET products on client machines with third-party security software is not recommended. You can use ESET AV Remover to remove other antivirus programs from your computer.

light-bulbEXAMPLE: automatically deploy ESET products on newly connected Windows desktops

1.Create a Dynamic Group, and name it without security product.

a.Make it a child group of the pre-defined group Windows computers > Windows (desktops).

b.Click New Template.

c.Add the following rule: Computer > Managed products mask.

d.As operator select not equal.

e.Select the mask icon_computer ESET protected: Desktop

f.Click Finish to save the group.

2.Navigate to Client tasks > ESET Security Product > Software Install.

a.Click New and give the task a Name.

b.Choose the package in the Settings section and set other parameters if needed.

c.Click Finish > Create Trigger.

d.In the Target section, click Add Groups and select Without security product.

e.In the Trigger section, select Joined Dynamic Group Trigger.

f.Click Finish to save the task and the trigger.

This task will be executed on clients connected to the dynamic group since this moment. You will need to execute this task manually on clients which were in the dynamic group before the task was created.

light-bulbEXAMPLE: enforce location-based policy

1.Create a Dynamic Group called Subnetwork 120.

a.Make it a child group of the All group.

b.Click New Template.

c.Add rule: Network IP addresses > IP subnetwork.

d.As operator select equal.

e.Enter the subnetwork you want to filter, for example, 10.1.120.0 (the last number has to be 0 to filter all the IP addresses from the 10.1.120. subnetwork).

f.Click Finish to save the group.

2.Navigate to Policies.

a.Click New policy and give the policy a Name.

b.In the expand_hover Settings section, select ESET Management Agent.

c.Make the policy change; for example, change the Connection interval to 5 minutes.

d.In the expand_hover Assign section, click Assign and select the check box checkbox_ok next to your group Subnetwork 120 and click OK to confirm.

e.Click Finish to save the policy.

This policy will be applied immediately to clients that are connected to the dynamic group already.

validation-status-icon-error WARNING

See policy removal rules to verify what happens to the applied policy settings when the client machine leaves the dynamic group (conditions matching the dynamic group membership are not valid anymore).

See other examples listed here.