Monitor ESET protection with the ESET Security check
The ESET Security check runs on the device and reads ESET Endpoint or Server Security locally — no cloud access, no credentials, no customer matching.
Written By Stefan Steuer
Last updated 8 days ago
The ESET Security check runs directly on the device. It reads the ESET product installed there — ESET Endpoint Security, ESET Endpoint Antivirus, ESET Server Security or ESET File Security — through eRmm.exe, the local management interface that ESET installs alongside the product. Everything the check reports comes from the machine itself: which protection modules are active, how old the virus signatures are, and what ESET has recently detected. No ESET PROTECT cloud console, no API credentials, no region and no customer-to-group matching are involved.
If you used the ESET PROTECT integration before
The ESET card under Administration → Integrations is gone, and it no longer needs to be there. The check kept the same identity when it moved onto the device, so every assignment you already made — on individual devices and through config packages — keeps working automatically. There is nothing to reconnect, nothing to migrate and nothing to re-create. The visible differences are the name, now ESET Security, and the fact that results come from the device instead of the cloud.
Prerequisites
- The device runs Windows. This check is Windows-only; on any other operating system it reports the failure "This check runs only on Windows."
- The octoja agent is installed on the device and connected.
- An ESET endpoint or server product is installed on the device. The eRmm interface ships with that product, so nothing extra is installed for the check.
- You need the Monitoring Check Management permission to add or edit checks.
You do not have to tell octoja where ESET lives. The check looks for eRmm.exe in three places, in this order: the path you entered under Path to eRmm.exe, then every product folder inside %ProgramFiles%\ESET, and finally the installation directory that ESET records in the Windows registry. Only a non-standard installation directory needs the manual path.
Add the check to a device
- Go to Devices and open the device.
- Click the Checks tab → Add Check → ESET Security.
- Keep the defaults, or adjust the thresholds described below.
- Click Add Check.
To roll the check out to many devices at once, assign it through a config package instead — see Assign checks with config packages. The check runs every 15 minutes by default.
Configuration options
The last two fields only appear once you switch on Show advanced options.
What the check reports
What the statuses mean
When the local query fails
If the check cannot get a usable answer out of eRmm, it reports a check failure and says why. It does not fall back to claiming that protection is off — an unanswered query is a collection problem, not a verdict on the device's security.
ESET Security or Antivirus Status?
Both checks look at antivirus, but they are not the same thing and can run side by side. Antivirus Status is the vendor-neutral check: it asks the Windows Security Center which antivirus product is registered and reports installation, real-time protection and definition age for whatever it finds — including ESET. ESET Security talks to ESET directly and therefore sees more: individual protection modules, the scanner module version, ESET's own advisories and the entries in ESET's threat log. Use ESET Security on devices where you know ESET is the product, and Antivirus Status where the vendor varies or you want one check across a mixed fleet.