Endpoint Protection

 View Only
  • 1.  In SEPM 12.1, from where we will find infection source I.P. address in Reports tab

    Posted Jul 02, 2013 05:14 AM

    In SEPM from where we will find infection source machine I.P. address in Reports tab. Generally we see only top infected clients or machines but not able extract the report to see top infection source in "Report" tab.



  • 2.  RE: In SEPM 12.1, from where we will find infection source I.P. address in Reports tab

    Broadcom Employee
    Posted Jul 02, 2013 05:17 AM

    login to SEPM -> Monitor -> Risk distribution by Attacker.

    If you have Risk tracer enabled, that area will be populated with the IP address of the bad machines.

    http://www.symantec.com/business/support/index?page=content&id=TECH94526

     



  • 3.  RE: In SEPM 12.1, from where we will find infection source I.P. address in Reports tab

    Posted Jul 02, 2013 05:20 AM

    Without enabling Risk tracer (disabled by default) the entries regarding the IP source will be empty.

    What is Risk Tracer?

    Article:TECH102539  |  Created: 2007-01-27  |  Updated: 2013-06-17  |  Article URL http://www.symantec.com/docs/TECH102539

     



  • 4.  RE: In SEPM 12.1, from where we will find infection source I.P. address in Reports tab

    Posted Jul 02, 2013 06:01 AM

    In SEPM Dashboard -> Favourite report -> edit -

    open windows ->select Risk in Report Type & Select Infected and at risk report in Report name.

    OK.



  • 5.  RE: In SEPM 12.1, from where we will find infection source I.P. address in Reports tab

    Posted Jul 02, 2013 06:32 AM

    HI, 

    Worms and threats that spread across networks by network shares have become more common in recent years. Risk Tracer is an optional feature in Symantec Endpoint Protection (SEP) that records information on what network source a threat has come from so that the root of the outbreak can be easily identified and fixed. 

    Risk Tracer can be extremely useful in informing what computers to isolate and scan. For illustration, export a Log History Report from the Symantec Endpoint Protection Manager (SEPM) and hide many of the columns that do not relate to Risk Tracer.
    Example: 
    "Monitors Tab" on the left hand pane. 
    "Logs" on the tab menu (Top of Screen)
    "Log Type:" Risk
    Default Filter
    "View Log" button
    Export Search Results.
    Import into Excel.
    Results below.

    http://www.symantec.com/docs/TECH102539

    Regards
    Ajin


  • 6.  RE: In SEPM 12.1, from where we will find infection source I.P. address in Reports tab

    Posted Jul 02, 2013 06:46 AM

    In addition you will get the source information from Network Threat Protection Logs.



  • 7.  RE: In SEPM 12.1, from where we will find infection source I.P. address in Reports tab

    Posted Jul 09, 2013 07:57 AM

    Hi

    1. Login to SEPM

    2. Goto Monitor tab

    3. Goto Log tab

    4. In the log type Select as "Risk"

    5. Select the Time Range

    6. Click on View logs

    7. Export the logs

    When you export the logs search for the tab source IP which will give the Source of attacker

    Note: This will be available only when the Risk Tracer is enabled

    Regards