Monitor Securepoint Antivirus Pro on your devices
The Securepoint Antivirus Pro check runs on the device itself and reports the GuardX service, real-time protection, signature age and threats to octoja.
Written By Stefan Steuer
Last updated 8 days ago
The Securepoint Antivirus Pro check runs directly on the device. The octoja agent reads the local state of Securepoint Antivirus Pro on Windows β the GuardX service, real-time protection, the age of the virus definitions, the quarantine folder and active threats β and reports it back to octoja. Securepoint offers no cloud API for Antivirus Pro, so reading the endpoint locally is the only possible source for this data. There is nothing to connect: no portal account, no access token, no customer matching.
Your existing assignments keep working
The check kept its identifier, so every assignment carries over on its own. Devices that already had Securepoint Antivirus Pro assigned keep it, config packages that contain it stay valid, and the check history is preserved. There is nothing to migrate and nothing to re-create.
Prerequisites
- A Windows device. The check ships for Windows on x64 and Arm64 only. On any other operating system it reports the failure This check runs only on Windows.
- Securepoint Antivirus Pro installed in its default location,
C:\Program Files\Securepoint Antivirus Pro. The check reads thelog,binandquarantinefolders below that path. - The octoja agent running on the device. It executes the check locally and needs to read the GuardX service, the Windows Application event log and the quarantine folder.
- Permission to assign checks β either directly on a device or through a config package.
Add the check to your devices
- For a single device: open the device in octoja, go to its checks and add Securepoint Antivirus Pro.
- For many devices at once: put the check into a config package and assign the package β see Assign checks with config packages.
The check runs every 15 minutes and works with its defaults β you only need to open the settings if you want to change thresholds or severities.
What the check reports
Configuration options
All seven settings are optional. Two of them sit behind Show advanced options.
Status messages and what to do
When the check cannot run at all
These are failures of the check itself, not findings about the antivirus. No values are reported alongside them.
Do not confuse it with these two
Three things in octoja carry a similar name. They are unrelated and can run side by side:
- Antivirus Status is the generic endpoint check. It reads what Windows Security Center knows about whichever antivirus is installed β Microsoft Defender, Bitdefender, Sophos, ESET, SentinelOne, CrowdStrike and others. It gives you a vendor-independent overview, but none of the Securepoint-specific detail such as the GuardX service, the quarantine count or the update log.
- Securepoint UTM (SNMP) is a vendor option inside the Network Firewall (Appliance) check. It monitors a Securepoint firewall appliance over SNMP β throughput, sessions, VPN, high-availability state and licensing. It has nothing to do with endpoint antivirus and is not assigned to workstations.