Forward Host Information
Host information forwarding sends information about eyeSight hosts to eyeInspect.
At the eyeInspect end, the eyeInspect Data Enricher receives and updates the host information in the Command Center database.
To enable host information forwarding, do the following:
- Select , and then select the Host information forwarding tab.
- Check the Enable host information forwarding checkbox.
- In the Interval (minutes) field, enter the desired time interval between
subsequent updates, in minutes. Note: It is recommended to calculate the interval duration as described below for better performance:
- Determine the total number of hosts across all eyeSight environments connected to the Command Center
- Divide this number by 120 and round off to the nearest whole number
to arrive at the interval duration in minutes.
For example, if the Command Center has two connected eyeSight environments, with 1000 and 2000 hosts respectively, the calculation would be (1000+2000)/120 = 22.5 ~ 23 minutes. This number can then be entered as the interval duration.
- Select the desired plugins/classification to export the respective properties.
The following table lists the various plugins/classification and respective
properties exported.
Plugin/Classification Exported Properties VMWare - IP Address
- Server Vendor
- Guest Hostname
- Mac address
- Guest OS
Switch - IP Address
- Switch Port Index
- Switch IP
- Mac Address
- Switch Port Name
Classification - Model
- Function
- Vendor and Model
- Class Vendor
- Operating System
Wireless - WLAN Detected Client Type
- WLAN Client Role
- WLAN Association Status
- WLAN Device PF/FQDN
- WLAN Device Vendor
- WLAN SSID
- WLAN Client VLAN
- WLAN Client Username
- Mac Address
- IP Address
- WLAN AP Name
- WLAN Authentication Method
- WLAN Client User Agent
- WLAN AP Location
- WLAN BSSID
- WLAN Client Connectivity Status
Groups eyeSight Groups - Select Apply to save.
Export Groups
Starting with Operational Technology plugin v3.2.1, users can export eyeSight group names as a custom property to eyeInspect. In eyeInspect Command Center, group names appear as a custom asset property called Groups.
Whenever a new IP is added to a Group in eyeSight, the Operational Technology plugin must be restarted manually to ensure the new Group is visible in eyeInspect. To restart the Operational Technology plugin, in Forescout Console, go to Tools > Options > Module, right click Operational Technology, click Stop, and then click Start.