Endpoint Protection

 View Only
  • 1.  Need to monitor when a client's Endpoint Protection is disabled.

    Posted May 07, 2012 07:12 PM

    I am setting up a new implementatino of SEP in my organization and was wondering if there is a way to monitor when a client's Endpoint Protectoni (or one of its components) has been turned off or disabled?  I am locking down the controls for that but also wanted to enable a monitor to alert me should someone or something get around those locks or if there is something wrong with the SEP client.

    Thanks.



  • 2.  RE: Need to monitor when a client's Endpoint Protection is disabled.

    Posted May 07, 2012 11:37 PM

    As i know there is nothing to configure to get alerts of disabled endpoint components and you have to monitor it day to day on SEPM.



  • 3.  RE: Need to monitor when a client's Endpoint Protection is disabled.
    Best Answer

    Broadcom Employee
    Posted May 08, 2012 02:12 AM

    Hi,

    Reports can provide clients status. But it's not possible to set alert when something wrong with SEP client.

     



  • 4.  RE: Need to monitor when a client's Endpoint Protection is disabled.

    Posted May 08, 2012 02:16 AM

    I have put this requirement into Idea you can check here:

    https://www-secure.symantec.com/connect/ideas/alerts-disabled-endpoint-components



  • 5.  RE: Need to monitor when a client's Endpoint Protection is disabled.

    Trusted Advisor
    Posted May 08, 2012 07:09 AM

    Hello,

    I would rather suggest you to go with Computer Status Report.

    Computer Status Displays information about the operational status of the computers in your network, such as which computers have security features turned off. These reports include information about versions, the clients that have not checked in to the server, client inventory, and online status.

    Reference:

    About Computer Status reports and logs

    http://www.symantec.com/docs/TECH95541

    About the different types of Symantec Endpoint Protection Manager Reports

    http://www.symantec.com/docs/TECH95538

    To add more:

    What do the different Notification Conditions for email alerts mean?

    http://www.symantec.com/docs/TECH91535

    Creating notifications in the Symantec Endpoint Protection Manager

    http://www.symantec.com/docs/TECH91622

    Hope that helps!!


  • 6.  RE: Need to monitor when a client's Endpoint Protection is disabled.

    Posted May 08, 2012 05:11 PM

    If you have a Security Information or Event Manager like SSIM, CISCO Mars, ArcSight you can do that, you can create a incident for that.

    However in SEP you can view it either from Home Page or you can add it in your daily Report/Checklist.



  • 7.  RE: Need to monitor when a client's Endpoint Protection is disabled.

    Posted May 09, 2012 12:40 AM

    Having to run a report to get the information seems kind of after the fact but I suppose it's better than nothing.  Thanks everyone for your comments/suggestions.