Endpoint Protection

 View Only
  • 1.  SEPM 12 Unmanaged Detector - Does it keep historical data?

    Posted Mar 07, 2014 09:14 AM

    The title of this might be confusing so will explain some more!  We use unmanaged detectors on SEP 12, one on each subnet.  My query is once SEPM has recieved a report of a "unmanaged" device does it keep that info on the notifications even when the device is no longer connected to the network?

    Our problem is we recieve a list of unmanaged devices and when it comes to pinging these 50% don't respond anymore or are false positives as the device that may have been on that IP has now changed as we use DHCP so the MAC that SEPM reports as unmanaged is no longer assigned to that IP.  Is there a way of:

    a) Checking the timestamp that SEPM was made aware of these.

    b) Clearing out old information from the database (stuff that is no longer live)



  • 2.  RE: SEPM 12 Unmanaged Detector - Does it keep historical data?

    Posted Mar 07, 2014 09:16 AM

    See here:

    https://www-secure.symantec.com/connect/forums/unmanaged-detectors-and-syslog

    Does not appear the log is created

    Great description on how the process works here:

    https://www-secure.symantec.com/connect/forums/how-unmanaged-detector-works#comment-8448451

    The SEPM gets the data from the client, the SEPM checks the IP address and MAC and if not present in the SEPM, it sends an alert.



  • 3.  RE: SEPM 12 Unmanaged Detector - Does it keep historical data?

    Posted Mar 07, 2014 09:29 AM

    So the only way to purge the "useless" data is to manually disable the unmanaged detector and then re-enable it?



  • 4.  RE: SEPM 12 Unmanaged Detector - Does it keep historical data?
    Best Answer

    Posted Mar 07, 2014 09:29 AM

    It does not seem to purge them at regular intervals, whenever there are false positives or IP addresses of systems which are not even in the network we just delete the unmanaged detector.

    Once we make unmanged detector again we never got those alerts.

     



  • 5.  RE: SEPM 12 Unmanaged Detector - Does it keep historical data?

    Posted Mar 07, 2014 09:34 AM

    Yes, that worked for us all the time :)



  • 6.  RE: SEPM 12 Unmanaged Detector - Does it keep historical data?

    Posted Mar 07, 2014 09:52 AM
    Correct


  • 7.  RE: SEPM 12 Unmanaged Detector - Does it keep historical data?

    Posted Mar 11, 2014 10:33 AM

    Thanks guys have just implemented that process and pleased to say we have now have a reduction in the unmanaged devices - make our job much easier!



  • 8.  RE: SEPM 12 Unmanaged Detector - Does it keep historical data?

    Posted Mar 11, 2014 12:32 PM

    Good to hear !! Have a wonderful day ahead..