Endpoint Protection

 View Only
  • 1.  IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 02:35 PM

    Hi,

    I got alerts from Symantec with subject "CRITICAL: NETWORK VIRUS DETECTED" about a few machines but when I check the IPS logs manualy for those machines, there are no logs found. I have tried all defined criteria's but no luck. This is something strange for me. Please advice.



  • 2.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 02:48 PM

    1. How long do you have the SEPM configure to store logs?

    2. Are the clients connecting to the SEPM to upload logs?

    3. If you check a client manually, does the entry show in the Security log?
     



  • 3.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 03:12 PM

    Thanks Brian,

    I am not sure about your last question but I am able to pull past week overall IPS logs so SEPM should store atleast a week logs for those machines too.

    Also I can see the detections in risk logs but not in network logs.



  • 4.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 03:23 PM

    So the logs are in SEPM but not on the client? How long are the clients keeping logs for?



  • 5.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 04:14 PM

    Risk logs are in SEPM but not the network logs for those machines detected in alert



  • 6.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 04:16 PM

    Those would be un der NTP >> Attack logs



  • 7.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 08:20 PM

    Yes

    But when I check this path NTP>>Attack logs there are no records found for those machines



  • 8.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 03, 2015 11:18 PM

    How long are NTP logs kept?



  • 9.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 04, 2015 07:48 PM

    A month long



  • 10.  RE: IPS logs disappeared from SEPM 12.1

    Posted Jun 09, 2015 11:19 AM

    Hi Shivam,

     

    The notification that you received means that there ia a "Risk Outbreak" in the network. The message "NETWORK VIRUS DETECTED" doesn't mean that it was detected by IPS. It means that the infection was detected in so many computers (Note: The number of computers is configured by you in the notification condition) and hence it is being considered as a network level threat. These detections are made by AVAS and not by IPS. Hence these detection logs will only be seen in risk log.