Endpoint Protection

 View Only
  • 1.  Instant email report

    Posted Nov 11, 2010 07:03 PM

    Is there a way to setup SEPM to send email report instantly when they dected a virus or a fail login?  I've been testing with eicar and it would give me the email report every hour instead of emailing me instantly.  Please help, I really appericated.



  • 2.  RE: Instant email report
    Best Answer

    Posted Nov 11, 2010 07:38 PM

    Set the damper to Auto and it will send instantly.

     



  • 3.  RE: Instant email report

    Trusted Advisor
    Posted Nov 11, 2010 08:08 PM

    Hello,

    Probable Causes:

    1) The damper setting for the notification may be preventing a series of EICAR detections from generating individual notifications, i.e. multiple EICAR detections within the damper period of a "single risk event" notification will generate only one notification for that period. Note also that if you do not see any "single risk event" notifications to acknowledge in the SEPM (under "View Notifications") this is by design. "Single risk" notifications are the only ones that cannot be configured to write a notification to the database -- they will, however, send email or run a custom batch file.

    2) The EICAR event may be getting deleted by database maintenance before the notification task can process it.

    To prevent this: In the SEPM, go to Admin > Servers > Local Site > Properties > Database tab, and uncheck "Delete EICAR events".