Endpoint Protection Small Business Edition

 View Only
  • 1.  Not getting emails from Application control rules

    Posted Mar 16, 2016 12:55 PM

    Who gets the email alert in the applications control? We are not recieving the alerts.

    symantec.png

    Thanks



  • 2.  RE: Not getting emails from Application control rules

    Posted Mar 16, 2016 12:56 PM

    We are getting emails about virus defs and System Event Notifications just not the application control rules.

    Thanks



  • 3.  RE: Not getting emails from Application control rules

    Posted Mar 16, 2016 12:57 PM

    Exact SEPM version?

    Do you have the alert configured under Monitors >> Notifications >> Notification Conditions >> Add >> Client Security Alert >> Application Control events



  • 4.  RE: Not getting emails from Application control rules

    Posted Mar 16, 2016 01:28 PM

    12.1.6306.6100 and yes we have client security alert and device control alers set.

    Thanks,

     



  • 5.  RE: Not getting emails from Application control rules

    Posted Mar 16, 2016 01:39 PM

    And this was working as expected prior to just recently? Did something change?



  • 6.  RE: Not getting emails from Application control rules

    Posted Mar 16, 2016 01:59 PM

    I dont think that it was ever working since I took over administration of the Symentc servers.



  • 7.  RE: Not getting emails from Application control rules

    Posted Mar 17, 2016 06:22 AM

    Is the Application Control rule working at all? You can check it at the client (View Logs > Client Management > Control Log) or at the SEPM (Monitors > Logs > Application and Device Control > [Log Content] Application Control > Advanced Settings > [Event Type] Application Control Rules).

    As Brian says, you have to configure the alert. By default, the condition and the damper settings are set with the goal to bother the admin not too much. You could set "condition" to "1 occurrences within 1 minutes" and the damper to "None" to increase the sensitivity of the alerts:

    AC_Notification.png

    In this setting above every Application Control event will trigger a notification and an email, not only until 3 events will happen within 1 minute.