End-of-Life (EoL)
What Data Does the GlobalProtect Agent Collect?
By default, the GlobalProtect agent collects vendor-specific
data about the end user security packages that are running on the
computer (as compiled by the OPSWAT global partnership program) and
reports this data to the GlobalProtect gateway for use in policy
enforcement.
Because security software must continually evolve to ensure end
user protection, your GlobalProtect gateway licenses also enable
you to get dynamic updates for the GlobalProtect data file with
the latest patch and software versions available for each package.
While the agent collects a comprehensive amount of data about
the host it is running on, you may have additional software that
you require your end-users to run in order to connect to your network
or to access certain resources. In this case, you can define custom
checks that instruct the agent to collect specific registry information
(on Windows clients), preference list (plist) information (on Mac
OS clients), or to collect information about whether or not specific
services are running on the host.
The agent collects data about the following categories of information
by default, to help to identify the security state of the host:
Category | Data Collected |
---|---|
General | Information about the host itself, including
the hostname, logon domain, operating system, client version, and,
for Windows systems, the domain to which the machine belongs. For
Windows clients’ domain, the GlobalProtect agent collects the domain
defined for ComputerNameDnsDomain ,
which is the DNS domain assigned to the local computer or the cluster
associated with the local computer. This data is what is displayed
for the Windows clients’ Domain in the HIP
Match log details (Monitor HIP Match |
Patch Management | Information about any patch management software
that is enabled and/or installed on the host and whether there are
any missing patches. If you want to configure
the Severity value for missing patches as
a match condition in your HIP object (Objects GlobalProtect HIP Objects <hip-object> Patch
Management Criteria
|
Firewall | Information about any client firewalls that
are installed and/or enabled on the host. |
Antivirus | Information about any antivirus software
that is enabled and/or installed on the host, whether or not real-time
protection is enabled, the virus definition version, last scan time,
the vendor and product name. GlobalProtect uses OPSWAT technology
to detect and assess third-party security applications on
the endpoint. By integrating with the OPSWAT OESIS framework, GlobalProtect enables
you to assess the compliance state of the endpoint. For example,
you can define HIP objects and HIP profiles that verify the presence
of a specific version of Antivirus software from a specific vendor
on the endpoint and also ensure that it has the latest virus definition
files. |
Anti-Spyware | Information about any anti-spyware software
that is enabled and/or installed on the host, whether or not real-time
protection is enabled, the virus definition version, last scan time,
the vendor and product name. |
Disk Backup | Information about whether disk backup software
is installed, the last backup time, and the vendor and product name
of the software. |
Disk Encryption | Information about whether disk encryption
software is installed, which drives and/or paths are configured
for encryption, and the vendor and product name of the software. |
Data Loss Prevention | Information about whether data loss prevention
(DLP) software is installed and/or enabled for the prevention sensitive corporate
information from leaving the corporate network or from being stored
on a potentially insecure device. This information is only collected
from Windows clients. |
Mobile Devices | Information about the mobile device, including
the device name, logon domain, operating system, app version, and
the mobile device network information to which the device is connected.
In addition, GlobalProtect collects whether the device is rooted
or jailbroken. To collect mobile device attributes and
utilize them in HIP enforcement policies, GlobalProtect requires
an MDM server. GlobalProtect currently supports HIP integration
with the AirWatch MDM server. For devices managed by
AirWatch, host information collected by the GlobalProtect app can
be supplemented with additional information collected from the AirWatch
service. Refer to Configure
Windows User-ID Agent to Collect Host Information for a list
of attributes that can be retrieved from AirWatch. |
You can exclude certain categories of information from being
collected on certain hosts (to save CPU cycles and improve client
response time). To do this, you create a client configuration on
the portal excluding the categories you are not interested in. For
example, if you do not plan to create policy based on whether or
not client systems run disk backup software, you can exclude that
category and the agent will not collect any information about disk
backup.
You can also choose to exclude collecting information from personal
devices in order to allow for user privacy. This can include excluding
device location and a list of apps installed on the device that
are not managed by a third-party mobile device manager.
Recommended For You
Recommended Videos
Recommended videos not found.