Endpoint Protection

 View Only
  • 1.  SEP 11 - receive report only if a computer is infected

    Posted Apr 08, 2009 08:04 AM
    Hi

    Isn't it possible to create a report in the SEP Manager that will send out a report only if a client is infected with virus or something else?

    /Lasse


  • 2.  RE: SEP 11 - receive report only if a computer is infected

    Posted Apr 08, 2009 08:44 AM
    Go to Logs -> Notifications and add a notification for risk/virus found


  • 3.  RE: SEP 11 - receive report only if a computer is infected

    Posted Apr 08, 2009 09:17 AM
    Hi

    pbogu's solution is satisfying.


  • 4.  RE: SEP 11 - receive report only if a computer is infected

    Posted Apr 08, 2009 10:54 AM
    Looks like there may be some important details missing, and/or just wrong (maybe unfiltered or untested?) information being passed...

    When SEPM is started (latest public release), there is no "Logs" button, tab, or link on the console.  If I check all of the navigation buttons on the left side, the only one with a "Logs" tab, button, or link, is the "Monitors" button.  So we go Monitors > Logs tab, but there is no place there to set up a notification for "risk/virus found" (or any other kind of notice, just filters for notices).  There is a Notifications tab though...

    If we try Monitors > Notifications tab, you can create and save a filter (of previously defined notifications - I guess), but nothing that is identified as "risk/virus found", and nothing yet for creating a notice.  There is a "Notification Conditions" button there though, which can be used to define a notification (I think - guessing again, and seems to be what the "Tell me more..." link indicates).  That seems to be what is needed to actually cause a notification (email message) to be sent when there is a virus detected.

    So, if my interpretation of this ultra user-friendly console is correct, you need to click "Monitors" button > "Notifications" tab > "Notification Conditions" button > Add...

    Depending on your needs, you may want to add 3 or 4 notifications to cover several areas of concern, including notifications for "Risk Outbreak" (multiple machines infected over a period of time), "New Risk Detected", "Security Alert Notices", and maybe "New Learned Application" if that is a concern.

    I don't know if any of this actually works, or if I'm even in the right ball park with it - looks to me like the right thing to do.  If you know a different or better/right way to get useful notices when a risk is detected, please share it.

    Good luck.


  • 5.  RE: SEP 11 - receive report only if a computer is infected

    Posted Apr 08, 2009 11:19 AM
    you are right there is no log tab. my bad.
    just a lot of time i'm using monitors -> logs ;)


  • 6.  RE: SEP 11 - receive report only if a computer is infected

    Posted Apr 08, 2009 10:32 PM
    I setup two notifications: Single Risk Event and New Risk Found.  Single Risk Event seems to notify each time something is detected whereas New Risk Found doesn't alert me about multiple computer with the same risk (and I think this is by design).  Prior to MR4, Single Risk Events weren't consitently sent, but since MR4, I don't think I missed a single one.