A check that ships with the platform, run by a PROPRIETARY rule on its Schedule.
These cover checks a rule's own query and function cannot express. Each takes no configuration on the rule; where a threshold applies it is a deployment-wide setting.
Values
| Enum Value | Description |
|---|---|
|
|
Flags a Security object none of whose antivirus products has reported its state within the deployment's window, meaning antivirus stopped reporting. An endpoint with no antivirus product isn't judged. Apply it to SECURITY. |
|
|
Flags an Endpoint still running an older agent than the latest stable build for its platform once that build has been available longer than the deployment's grace period, meaning auto-update isn't reaching it. Apply it to ENDPOINT. |
|
|
Flags an Endpoint whose consecutive positions imply travel faster than the deployment's maximum speed, which can mean the endpoint, or its location reports, were tampered with. Short jumps within the positions' margin of error aren't judged. Apply it to ENDPOINT. |
|
|
Flags an object that has not been seen for longer than the deployment's staleness window. A change-driven rule cannot catch this: an object that stops reporting produces no change to evaluate. |
|
|
Flags a SoftwareUpdatePreferences object whose last successful operating system update installation is older than the deployment's maximum age. Only Windows reports an installation time; macOS and any endpoint reporting none aren't judged. Apply it to SOFTWARE_UPDATE_PREFERENCES. |
Used by
RuleBodyProprietarytype: The body of a PROPRIETARY rule: the built-in check the rule runs.RuleBodyProprietaryInputinput: Input variant of RuleBodyProprietary.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.SecurityThe security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.SoftwareUpdatePreferencesThe operating system update configuration of an Endpoint and the updates currently available to it.
Example
Example
"ANTIVIRUS_STATE_STALE"