Any way to configure "unmanaged detector" to ignore certain things?
I've got a situation here where servers and other things are brought online and I'm not told and there's no SEP or even SAV on them.
I can enable one of the SEM servers as an "unmanaged detector" and that's GREAT, except EVERY HOUR, I get an email showing a list of unmanaged machines.
Two things:
Every hour is a bit much, every 2 hours would be fine
and
it shows SWITCHES, ROUTERS and the ESX boxes in that email. I'd rather it ignore things that can't possibly respond or that are not Windows....
A ASA5505 is not a Windows device. Neither is an ESX box. It has an IP address and that's apparently enough for the unmanaged detector to say it's running but not protected.
IS IT POSSIBLE to tell this thing to send an email out once a day, or twice a day or every 2 hours instead of every hour?
And can I feed it a list of IP addresses to IGNORE? I don't need to sort through a list of dozens of things just to find one possible device that needs attention.
Thanks...............
Comments
OOPS - JUST found a place to
OOPS - JUST found a place to put a list of IP to ignore - however, I must manually type in many many IP addresses.
Can we get an import function, or can it read a text list?
You have to enable that device before you can even see the configure screen....
Now to get it to stop alerting every 60 minutes..................
My sites - http://theamcpages.com & http://antique-engines.com
Toy:
Shadow:
Exclude detecton of an IP address range
If Excluding IP range Helps you..You can check this
Title: 'How do I configure exceptions for the "unmanaged detector" from Symantec Endpoint Protection Manager (SEPM)?'
Document ID: 2009081719391348
> Web URL: http://service1.symantec.com/support/ent-security.nsf/docid/2009081719391348?Open&seg=ent
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
To change the amount of time
To change the amount of time between notifications, goto Monitors, notifications, notification conditions and change the damper setting:
Would you like to reply?
Login or Register to post your comment.