Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

Detection Rules Altiris 7.5 Software package examples

Created: 14 Nov 2013 | 2 comments

I seem to be running into various scenarios where I need to manually add Detection rules with the built in editor in Altiris 7.5. We used both x64 and x86 machines so using an OR operator for example doesn't seem to always work especially when using program files (x86) or program files directories in the same detection rule for the same software package. Is there a guide with some examples? I've searched and found some info but nothing digs deep into this area. They mostly just mention how to get to it and high level functionality.

Operating Systems:

Comments 2 CommentsJump to latest comment

Dmitri Dragunov's picture

Hi,

Please refere to the next KB article related Creating or editing inventory rules http://www.symantec.com/business/support/index?page=content&id=HOWTO93595

There is a note (this may resolve your porblem): 

The AndNotOr operators apply to the rules, which reside under the corresponding operator in the expression tree in the left pane. The rule does not work, if the operator and the rules, to which it must apply, are on the same level in the expression tree. Please see the example of correct usage of the Or operator below:

or_and_operator.png

Regards,

Dmitri

galforelembeck@hotmail.com's picture

Thanks. That seems to do the trick as long as you start with And - Or and keep each entry separated with that.