Stop and start Forescout eyeSight policy Actions

You can stop and start specific actions that are applied by policy rules.

When you stop an action:

  • Actions currently affecting endpoints are stopped.
  • From now on, actions are not applied to endpoints that match the policy condition.

You may need to stop actions to test a policy before enforcing sanctions, i.e., only detect endpoints that match a policy.

When you stop or start actions for main policies, related sub-policy actions are also stopped or started.

One-time actions, such as email and HTTP redirection, can only be stopped if they are defined in Actions schedules.

To tell whether an action is stopped:

  • Look at the action icon: Action icons are grayed out if stopped.
  • Check the Start or Stop Rule Actions dialog box: Select the policy or sub-policy, and then select Stop Policy Actions or Start Policy Actions to see the stopped and started actions.

To stop or start an action:

  1. In the Views pane of Home view, right-click a policy or sub-rule in the Policies folder, and then select Stop Policy Actions or Start Policy Actions. The Stop Action or Start Action dialog box opens.
  2. Select the actions you want to stop or start.
    Note: You can also edit the action definitions here.