Endpoint Protection

 View Only
  • 1.  Browser Intrusion notifications

    Posted Aug 04, 2014 09:36 AM
      |   view attached

    Hello,

    We have configured the client security alert notification type to send notifications by email when any of the following event types are detected:

    Compliance Events
    Network Threat Protection Events
    Traffic Events
    Packet Events

    As I understand it Network Threat Protection in SEP is comprised of Network intrusion prevention and browser intrusion prevention. The notifications do arrive for network intrusion prevention events but nothing for browser intrusion prevention events.  I know this because we had a browser intrusion event on 7/30 which appeared in a scheduled report the following day but the notification alert was not received.

    *attached screenshot of the client security alert configuration*

    Matt



  • 2.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 09:38 AM

    Yea you would/should get these for both network and browser, what's the exact version here?



  • 3.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 09:41 AM

    Hi Brian

    We're on 12.4104.4130



  • 4.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 09:49 AM

    Strangely the console reports this as 12.1.4100.4126

    I obtained that via help -> about

    nm the first is the console manager version :)



  • 5.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 09:52 AM

    Have you ever gotten an alert for browser IPS? Sounds more like an alert was just missed and it happened to be for the browser IPS.



  • 6.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 10:35 AM

    I don't believe i've ever noticed a browser IPS alert - we only enabled the client security alerts around 2 months ago.  What do you mean "an art was just missed" ?



  • 7.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 10:40 AM

    Sorry, meant "alert", just corrected it :)

    In all honesty, you may want to check in with Symantec.

    You can try deleting and re-creating the event. The main issue is I doubt you can easily re-produce this problem unless you know which malicious site(s) to visit.



  • 8.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 10:43 AM

    Okay i'll give the recreate a shot at least - i agree re-producing will be a problem but at least it shows up as a report so we should be aware if another occurs.

    If it doesn't work i'll open a Symantec ticket.

    Will update this when i know more!



  • 9.  RE: Browser Intrusion notifications

    Posted Aug 04, 2014 10:46 AM

    Sounds good :)