Release Notes for Reqo Maestro for ePO Version 4.6.5 © 2008 Reqo, Inc. All Rights Reserved ============================================================ NEW FEATURES IN VER 4.6.5 General: ----------------------------- 1. New login type 'Account Admin' added. Sole purpose of this account is to add/modify/delete users. Other than user management 'Account Admin' has the same set of privilegies as 'Admin' users. If at least one user of 'Account Admin' type is created then permissions to add/modify/delete accounts are transfered from 'Admin' users to 'Account Admin' users. To give back account management privilegies to 'Admin' all 'Account Admin' users need to be removed from the system or have their account type changed to 'User' or 'Admin'. 2. Administrator auditing improved to include all product configuration changes. Improved report can be found under tab Settings > User Management > Auditing Report. Reports ----------------------------- 1. Report 'Product Deployment' reporting on all products. 2. Reports 'Server Events' and 'Replication Events' moved from Settings tab to Reports. These reports now can be scheduled and emailed. BUG FIXES: 1. Fixed bug on Settings page when link to reports 'Server Events' and 'Replication Events' failed in case when corresponding module is not installed. ============================================================ NEW FEATURES IN VER 4.6.4 Queries ----------------------------- 1. Added timestamp to error message for failed scheduled queries. 2. Added schedule period of 1 Hour. 3. New time variables added to Event Date and Last Comm Date filter value. BUG FIXES: 1. Fixed bug when background thread caused application server to hang after few hours. 2. Fixed bug when Site information from Query schedule was removed after Query was saved. 3. On Query schedule dialog fixed Site selection functionality. ============================================================ NEW FEATURES IN VER 4.6.3 General: ----------------------------- 1. Enterprise Edition installation supports Windows authentication. Settings ----------------------------- 1. Improved performance of User Site permissions editing screen. BUG FIXES: 1. Fixed bug in Maestro cache job settings causing Initialize step not to get executed. 2. Added custom command timeout to the process of Adding ePO source in Enterprise Wizard. 3. Fixed CSV export for Duplicate Agent GUID report. 4. Fixed bug in Products by Groups report. ============================================================ NEW FEATURES IN VER 4.6.2 General: 1. Application supports Windows authentication on Maestro database. BUG FIXES: 1. In Enterprise Edition fixed bug when configuration for Retention policy for Events_VSEBehaviourBlock table was not shown. ============================================================ NEW FEATURES IN VER 4.6.1 BUG FIXES: 1. Fixed Events caching for ePO version 4.x. ============================================================ NEW FEATURES IN VER 4.6 General ----------------------------- 1. Support for ePO version 4.0 added. See Installation Manual for detailed upgrade instructions. 2. Help updated and points to http://www.reqo.com/maestrohelp. Monitoring ----------------------------- 1. HIPs added to the list of Products under Product Deployment report where applicable. ============================================================ NEW FEATURES IN VER 4.5.1 Reports ----------------------------- 1. New Time Periods added to the Report parameters. 2. Schedule period of '8 hours', '1 day', and '2 days' added. BUG FIXES: 1. Fixed emailing and scheduled emailing of 'Duplicate Nodes' report. 2. Fixed Period Variable feature for scheduled reports. 3. Report 'DAT Deployment Summary' fixed. ============================================================ NEW FEATURES IN VER 4.5 Monitoring ----------------------------- 1. Added time periods to the Products menu for 'Product Deployment' report under Deployment tab. 2. Node last communication date and time filter added to 'Product Deployment' report under Deployment tab. Queries ----------------------------- 1. New Grouping feature added. User can specify to return grouped results from the query, as well as number of occurrences. 2. New Query parameter 'Rule Name' added under 'Threat Events' section. Reports ----------------------------- 1. Added emailing and scheduled emailing feature for the reports. Report email sender is configured in Global Settings under 'Global Maestro email settings'. 2. Ability to save reports with variables. 3. Default page for Reports tab redesigned. 4. New report 'Product Deployment' added. Settings ----------------------------- 1. New feature 'Active Directory Validation' added under 'User Management' section. 2. New type of Log 'AD Validation Log' added under 'Service Log Files' section. It will log Active Directory Monitoring process activity. 3. New setting 'Active Directory Monitoring Frequency (Days)' added to 'Global Settings' page. 4. New report 'Server Events' added under 'System Info' section. 5. New report 'Replication Events' added under 'System Info' section. BUG FIXES: 1. Fixed bug on Monitoring page when filtering threats by Threat type was broken after the data grid is sorted or paged. ============================================================ NEW FEATURES IN VER 4.4.6 Monitoring ----------------------------- 1. New report called 'Node List' added under Deployment tab on Monitoring page. BUG FIXES: 1. Fixed problem with time on Query Schedule dialog. 2. Fixed URL issue with Query Schedule in the environment where 'localhost' is not resolved. 3. Fixed problem with Calender time settings. ============================================================ NEW FEATURES IN VER 4.4.5 General ----------------------------- 1. Maestro cache job steps reorganized to improve performance. 2. Increased server process execution timeout to 10 minutes. 3. Improved application responsiveness during execution of long processes. Query ----------------------------- 1. Improved performance of the Lookup dialog. Site Info ----------------------------- 1. Added Export Site Contacts to Site Info menu on ALL SITES. Settings: ----------------------------- 1. Moved default Monitoring Stats view settings from web.config to Global Settings section. BUG FIXES: 1. Fixed request timeout problem in Query Lookup dialog. 2. Fixed Query results grid sorting. 3. Fixed bug when Date filter value was not retrieved correctly upon loading of saved Query. ============================================================ NEW FEATURES IN VER 4.4.4 Query ----------------------------- 1. Added Site selection on Query Schedule/Email dialog screen. 2. Added Preloader control to Run Query Grid window to avoid browser timeouts. Site Info ----------------------------- 1. Site Info screen redesigned. BUG FIXES: 1. Fixed owner information on Scheduled Queries admin screen. 2. Fixed permissions problem on Site tree. ============================================================ NEW FEATURES IN VER 4.4.3 Monitoring ----------------------------- 1. DAT/Engine Deployment - Advanced and Product Stats on Monitoring page were changed to show global top 7 DATS and top 2 Engines. It used to show top records for selected site. 2. Improved performance of Monitoring page. Query ----------------------------- 1. Current query will not get reset after saving. 2. Users can remove additional field criteria. 3. Copy Query feature added to Query sub-menu. 3. New menu items for Schedule Query and Email Query added. 4. Improved Query emailing and scheduling user interface. 5. New advanced Email Address lookup dialog used in Email Query and Schedule Query screens. Settings ----------------------------- 1. Enabled Rights button in User Management module for administrator's profile. 2. CVS export added to all four sections of Detailed ePO Statistics. 3. For Enterprise Edition added 'Reinitialize caching' button on Detailed System Statistics page. When clicked it will reinitialize cache settings to repopulate all cached data next time Maestro cache job runs. 4. New advanced Email Address lookup dialog used in Alert editing for My Alerts. BUG FIXES: 1. Fixed invalid page after updating Contact Information. 2. Fixed OS Deployment History graph legend. 3. Fixed export of Site Contacts to Excel spreadsheet. ============================================================ NEW FEATURES IN VER 4.4.2 General ----------------------------- 1. Added cleanup of History table to the first step of the Maestro cache job. Query ----------------------------- 1. Added new Filter type 'Not Exists'. Use this Filter in case of searches when Filter value does not exist. For example, to retrieve the list of computers that do not have VIRUSSCAN 8.5 you can select Filter 'Not Exists' and set filter value 'VIRUSSCAN 8.5'. Reports ----------------------------- 1. New report 'Duplicate Agent GUID' added. BUG FIXES: 1. Fixed Maestro database upgrade script. In release 4.4.1 upgrade was timing out on big History tables. ============================================================ NEW FEATURES IN VER 4.4.1 BUG FIXES: 1. Fixed bug when exporting to CSV file results from 'Duplicate Nodes Report' report. 2. Report 'VS 8.x Access Protection Rules' was not showing graph image and not using correctly report parameters in certain cases. 3. For Enterprise Edition fixed System Info screen on Settings tab. Screen was not showing ePO Source Databases. 4. New 'ePO 3.6.1' DAT and Engine format is fixed in Site compliance report and cached Computer properties. 5. Fixed Lookup for 'OS Language ID' and 'Action Taken' in Queries. ============================================================ NEW FEATURES IN VER 4.4 Monitoring ----------------------------- 1. Added cache feature to Advanced view of connected Nodes on Monitoring page. 2. On Graph section of Monitoring page added feature for selecting graph period. On top-right section report period text was turned into menu shortcut link activated by clicking mouse button over it. Query ----------------------------- 1. Introduced Variable feature to filter value. Some fields now can have variables that user can set as filter value. Fields with variables will be colored green. Variables will be replaces with real data at the queury run-time. For example, instead of looking up latest DAT version user can select |LatestDAT| variable, and Maestro will replace it with latest DAT version at the time query executes. 2. New option 'Email Query results' is added to the Queries Run menu. It allows users to email Query results to a recipient(s) instead of getting it on the screen. Email subject, body, and recipient list can be entered in the Email Parameters dialog window that appears upon selection of this menu option. 3. In 'Email Query results' screen added ability to pick Site contacts as email recipients. 4. New feature 'Scheduled email query results' allows user to schedule sending Query results by email. In addition to email parameters user can also specify frequency and start date and time of the schedule. 5. Due to recent ePO changes to DAT and Engine format two new columns added to Query criteria: Normalized DAT and Normalized Engine. For example, DAT versions '4.0.4849', '4849.0000', and '4849' will have one normalized DAT version equal '4849'. Same logic applies to new formats of Engine versions. Reports ----------------------------- 1. Added ThreatType filter to 'Detailed Threats' and 'Nodes with Threats' reports. 2. New report called 'Rule Violations' added under Reports tab in Coverage menu. It gives user ability to report on computers violating given Policy. Policy violated rule, OS Type, and OS Platform can be added as a parameters to this report. 3. Reports Site map added as a default page. Site Info ----------------------------- 1. Menu layout changed to correctly reflect the content. Settings ----------------------------- 1. Added cache setting for Advanced view of connected Nodes on Monitoring page. 2. Added setting for maximum number of records sent inside the email. It is located under Global Settings in Miscellaneous section. Default is set to 1000. 3. In Alert settings added ability to set different filter variable, like 'Begins With', 'Ends With', etc. 4. Added more statistics on orphaned records in ePO Database Info under Miscellaneous section. 5. Administraion screen for Scheduled email queries created. It allows Maestro administrator to monitor all scheduled queries, its parameters and duration. Administrator can also change, disable, and delete scheduled queries. 6. Settings Site map added as a default page. 7. New feature in Options menu to allow admin to add/delete/update Contact types. Alerting ----------------------------- 1. Alert email contains name of the person who defined that alert. 2. Virus type is added to alert filtering. 3. Alerting service is moved from Windows service into Maestro application process. All Alerting logging is done now into database. Installation also modified to remove Alerting Service step. BUG FIXES 1. Fixed Average Hardware view on Monitoring page 2. Fixed problem with crashing SiteInfo page when IPAddress in ComputerProperties table in ePO source database was incorrect format. 3. Block applications report filters parameters by selected Site. 4. Fixed number of bars in Top Threats table for graph on Monitoring page. 5. In Configure Event Retention Policy screen sorting by Age is fixed. 6. Fixed installation bug when overwriting existing Maestro database did not ask for new administrator password. 7. Cache age was fixed in case when there was no data. Now it will show 'No Data' instead of some huge incorrect data. 8. Fixed issue when admin user, other than default, moved Global Query to Personal and it would disappear. ============================================================ NEW FEATURES IN VER 4.3.1 BUG FIXES 1. Fixed Top historical threats caching problem 2. In DAT Deployment history fixed problem when exaclty 1 hour was not showing in the grid 3. In User Management Auding Report parameters added time to calendar 4. In Settings Site Info Fields fixed tooltip for Delete button 5. Fixed sorting by last login date in User Management screen 6. Fixed count discrepancy between Query lookup count and Query results ============================================================ NEW FEATURES IN VER 4.3 General ----------------------------- 1. Changed the default grid search behaviour. Users will now be required to press Enter after entering their search criteria. This setting can be reversed back to the original behaviour in Settings -> Global Settings -> Grid Search 2. Merged 5 Maestro jobs into one Maestro_CacheJob for performance improvements. 3. Made various changes to Alerting and Caching mechanisms to improve performance in very large environments. Monitoring ----------------------------- 1. Added Legacy node statistics control. This shows basic node information as in versions prior to 4.0. 2. Added threat type filtering in Top Threats controls. Queries ----------------------------- 1. Added time to event date field 2. In Lookup Available Values dialog new section was added giving ability to select multiple values or enter values manually Site Info ----------------------------- 1. Added three new columns to IP Ranges grid: Inside (count of the Computers under the selected site with IP Address falling into that Range), Outside (count of the Computers with IP Address falling into that Range but not from selected site), and Ratio graph (percentage ratio between previous two numbers) 2. Counter columns from item 1 have a drill-down report that lists Computers from each category Settings ----------------------------- 1. Under Global settings new configuration added for customizing Grid Search label and behaviour. See point 1 in General section above. BUG FIXES 1. Fixed sorting by Computer name in Query search result ============================================================ NEW FEATURES IN VER 4.2 General ----------------------------- 1. Added configurable application title (configured in Web.config) 2. Changed default SQL Recovery Model for Maestro database to SIMPLE 3. Changed default configuration to show detailed error information when browsing on the server itself Queries ----------------------------- 1. Added time to event date field 2. Added descriptive value lookup to OS Language ID field 3. Added Grid to Query lookup dialog boxes resulting in much faster performance with large amount of data 4. Added lookup ability to the following fields in Computer Properties section - Computer Name - User Name 5. Added lookup ability to the following fields in Operating System Properties section - OS OEM ID 6. Added lookup ability to the following fields in Network Properties section - IP Address - IP Host Name - Net Address - IPXAddress 7. Added lookup ability to the following fields in Hardware section - CPU Speed - CPU Num 8. Added lookup ability to the following fields in Threat Events section - Infected Computer - Infected IPAddress - User Name - File name 9. Added Source IPAddress field in Threat Events section Reports ----------------------------- 1. Added Grid control with paging to the following reports and their drilldowns: - DAT Engine Coverage Report - Top 10 Threats - No Antivirus Protection Report - DAT Deployment Summary Report - Detailed Threats Report - Nodes With Threats Report - Top Historical Threats - Active Not Protected Report - First Threat Occurrence Report - Top 10 Attackers - Login Auditing Report - VS 8.x Unwated Programs Report - VS 8.x Access Protection Rules Report - Compliance Report - Infected Nodes Report - Duplicate Nodes Report - Site Permissions Report 2. Added time to date parameters on relevant report parameter screens BUG FIXES 1. Addressed performance issues with Site Permissions Report in environments with very large number of sites and users 2. Addressed performance issues with Site Permissions screen in environments with very large number of sites 3. Addressed layout issues on the Monitoring page in environments with very large number of nodes 4. Fixed Historical Viruses Report from crashing in some environments 5. Addressed performance issues with Nodes With Threats Report in environments with very large number of daily threat events 6. Addressed performance issues with First Threat Occurrence Report in environments with very large number of threat events 7. Addressed graph showing sites with no data on DAT Deployment screen ============================================================ NEW FEATURES IN VER 4.1.4 General ----------------------------- Added support for SQL Server 2005 Reports ----------------------------- 1. Changed logic to include data up to end date parameter (previously end date was not included) for the following reports: - Blocked Applications Report - VS 8.x Access Protection Rules Report - VS 8.x Unwanted Programs Report - Infected Nodes Report - Detailed Threats Report - Top Historical Threats Report - Top 10 Attackers Report - Top 10 Threats Report - DAT Deployment Summary Report 2. Changed logic to include nodes with no AV product software on the Active Not Protected Report. Settings ----------------------------- 1. Added GUI for editing Engine Exclusions that effect Monitoring page DAT/Engine Deployment - Advanced control 2. Added GUI for editing Product Abbreviations that effect Monitoring page Product Deployment control 3. Added GUI for editing OS Abbreviations that effect Monitoring page OS Deployment control 4. Added Site Permissions Report BUG FIXES 1. User Permissions screen - fixed tree right click functionality 2. Fixed reports graphs breaking under certain date conditions 3. Fixed drill down inconsistencies in Nodes with Threats control on Monitoring page ============================================================ NEW FEATURES IN VER 4.1.3 Monitoring Page ----------------------------- 1. Added TVD Description and MAC Address to the detailed Virus List CSV export under Top Threats by Instances/Nodes Site Info ----------------------------- 1. Added ability to toggle paging of site details in the grid on the Sites Chart screen. BUG FIXES 1. Addressed performance issues with Sites Chart screen in certain environments. 2. Addressed performance issues with DAT Deployment Summary report in certain environments. 3. Addressed licensing issues with various GUI controls in certain environments. ============================================================ NEW FEATURES IN VER 4.1.2 Queries Page ----------------------------- 1. Reorganized menus into buttons with drop-down menu functionality to improve user experience. 2. Added save and save as functionality to queries. ============================================================ NEW FEATURES IN VER 4.1.1 Monitoring Page ----------------------------- 1. Updated link to McAfee Threat Library 2. Added new product abbreviations for GroupShield for Lotus Domino and NS Netware Reporting Page ----------------------------- 1. VS 8.x Access Protection Rules Report: - Added Computer Name, Process Name, File Name, TVD Id parameters - Added CSV export 2. DAT Deployment Summary Report - Added Node Communication Period parameter - Added Running Total Columns - Added CSV export BUG FIXES 1. Fixes for duplicate nodes in DAT Engine Coverage Report 2. Addressed performance issues with Current Site Compliance drill downs in certain environments ============================================================ NEW FEATURES IN VER 4.1 Monitoring Page ----------------------------- 1. Added configuration options to switch to Classic View as default in Web.Config Queries Page ----------------------------- 1. New field: - TVD Event Description - Event Product Name - Event Product Version Reporting Page ----------------------------- 1. Infected Nodes Report 2. Duplicate Nodes Report 3. Added Path column to DAT/Engine Coverage Report Settings Page ---------------------------- 1. Additional new Active Directory authentication method for user accounts using LDAP 2. Added License History report ============================================================ NEW FEATURES IN VER 4.0 Monitoring Page ----------------------------- 1. New controls on Monitoring page: - DAT/Engine Deployment - Advanced - Average Hardware - Product Deployment - Top Threats by Node - Current Site Compliance - Historical Site COmpliance - DAT Deployment History - DAT Release History - OS Deployment History - Service Pack History - Product Deployment 2. Updated Classic view 3. Added statistical drilldowns throughout Monitoring Page 4. Drilldowns can be adjusted/saved/shared using Maestro Query engine 5. Top Threats by Instances/Nodes now display all threats found for the selected period 6. Added new Grid control with advanced features, e.g. on the fly filtering/paging/sorting/column resizing/grouping/column reordering 7. All Monitoring page controls can be printed/previewed separately Queries Page ----------------------------- 1. New fields: - Computer Path - Hot Fix - OSOEMID 2. Organized fields into logical groups 3. Added rename feature for saved queries 4. Added Preview sQL feature 5. Added Run Query using new advanced Grid control Reporting Page ----------------------------- 1. Compliance Summary Report Site Info Page ----------------------------- 1. Added Sites Pie Chart for sub sites of any selected site 2. New Query IPs Tool Settings Page ----------------------------- 1. Added advanced Grid control to the User Management Screen 2. Improved performance and layout of the site permissions screen Miscellaneous ----------------------------- 1. Maestro now heavily relies on SQL Agent jobs 2. Moved Caching functionality to a SQL Agent job (Caching Service has been decommissioned) ============================================================ NEW FEATURES IN VER 3.2 1. New report: VS 8.x Access Protection Rules Report 2. New report: VS 8.x Unwanted Programs Report 3. Ability send test email (this can be used for troubleshooting mail settings) 4. Optimized performance of alert cache calculation 5. Optimized precaching process during initial installation 6. Introduced application access rights framework. User logins can be now disabled from View & Manage Contacts/Accounts screen 7. Optional user management integration with Maestro for SecurityExpressions BUG FIXES 1. Fixed loading of currently selected item in Reports and Settings (red bullet) 2. Fixed collation related schema issues for new installations 3. Fixed caching service from halting when losing connection to the SQL Server ============================================================ NEW FEATURES IN VER 3.1 1. Ability to use last communicate date field in Queries 2. Integration of Site Contacts screen and Contact Management 3. Product settings drill downs are now available in Computer Properties screens (Standard Edition) 4. Computer Properties screen is available from Queries results containing computer name 5. Detailed ePO/System Diagnostics: TVD Information has been split out of Events information to allow faster access 6. Detailed ePO/System Diagnostics: Full table row counts added to Database Usage information 7. Clear log feature added to Services Log Files 8. Various performance improvements due to relaxed locking scheme BUG FIXES 1. Fixed reseting of permissions when saving contact details 2. Site information fields are now editable by regular users based on site information field editing settings 3. Added extra logic to filter out invalid future last communication dates when used to calculate active nodes ============================================================ NEW FEATURES IN VER 3.0 1. Group Tree - ability to navigate epo data both by sites and groups underneath them. 2. Group privileges - ability to assign site and group level access to users. 3. Improved performance of caching and reports 4. Site fields - ability to set up custom site information fields. 5. Centrally controlled time out settings 6. License tool - moved licensing abilities to a GUI tool available to admins with access to the web server. 7. Patch tool - automated patching of sql 8. Form based authentication 9. Event logging - all errors are now logged in EventLog on the web server, under Application -> Maestro 10. Password encryption - maestro user passwords are now encrypted in registry 11. Removed event filter in queries - now all events will show up 12. GMT time for all dates - all date/time fields are now in GMT 13. Inheritance of site and group access rights BUG FIXES 1. Fixed deleting of queries 2. Data no longer cached in lookup popups 3. Fixed error messages for registry errors, no database connection, bad user. 4. Fixed collating settings 5. Fixed progress bar hanging with few events 6. Fixed of active nodes calculation problem due to days prior to 1754 7. Fixed alert service being disable due to the missing encryption settings 8. Caching performance enhancements 9. Fixed account permissions not being saved when no recursive sites have been selected. ============================================================