Endpoint Protection

 View Only
  • 1.  SAV for Linux, ignoring alerts, only send email

    Posted Jan 24, 2012 03:09 AM

    Hi all!

    Im having trouble finding any documentation of making Symantec Antivirus for Linux ignoring threats, and just send their virus-definition to the specified email-adress. I need this action only while doing the weekly scheduled scan.

    For further informaion, pls dont hesitate to ask. :)

    Thx in advance



  • 2.  RE: SAV for Linux, ignoring alerts, only send email

    Posted Jan 31, 2012 11:56 AM

    Hi Dddoe,

    Do you mean that you wish for SAVFL just take the action of "log only" when a threat is identified-?

    Is there any specific reason that you wish for this "log only" action (fear that certain files will be detected in error/ False Positive)?  I really recommend leaving the actions at the default so that any malicious files are quarantined or deleted. 

    Regarding emails.... It is possible to configure SAVFL with SAVFL Reporter to send logs about detections to the SEPM.  The SEPM can then be configured to create notifications that are emailed to admins or other addresses.

    Hope this helps! 

    Mick