Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SSIM 4.7 - Creating Rules - Symantec Event Code

Created: 13 Jul 2010 | 2 comments
aveiga's picture
0 0 Votes
Login to vote

Hi, I'm reading about multicondition rules from manual

Symantec_Security_Information_Manager_User_Guide.pdf

and on page 92 there is an example that uses Symantec Event Code 722. Where can I obtain this list so that I can write my own rules?

Tks!

Discussion Filed Under:

Comments

DVorel's picture
30
Jul
2010
0 Votes 0
Login to vote

Hi Aveiga,

Symantec doesn't provide list of Symantec Event Codes o/

The only way how you can obtain list of Symantec Codes is to create own query based on unique Symantec Event Codes over last N days/months and then you will have list of all Symantec Codes, which are collected in SSIM.

I suggest create another query based on Vendor Signature too. The best way is to export the selection to the XLS, then you will have base for creating Queries or Correlation Rules...

HunterFighter's picture
29
Aug
2010
0 Votes 0
Login to vote

Is there any guide to collect

Is there any guide to collect those Symantec Codes?