Data Center Security

 View Only
  • 1.  Symantec Data Center Security: How do you confirm an intrusion

    Posted Aug 13, 2014 09:19 PM

    Hello everyone,

    I have been using SEP for years. It is obvious when a risk or threat is detected. It is identifed in the logs and you may get a pop-up.

    I have recently started using Symantec Data Center Security. From what it looks like there are MANY events generated. Out of all of these events how do you identify that you actually have an intrussion incident as opposed to one of 10,000 other benign logged event?

    Kind regards

    Cameron



  • 2.  RE: Symantec Data Center Security: How do you confirm an intrusion

    Posted Aug 14, 2014 05:49 AM

    Are you referring to DCS:SA (old name Critical System Protection) or the AV product DCS:S?



  • 3.  RE: Symantec Data Center Security: How do you confirm an intrusion

    Posted Aug 15, 2014 02:31 AM

    DCS:SA



  • 4.  RE: Symantec Data Center Security: How do you confirm an intrusion
    Best Answer

    Posted Aug 15, 2014 03:51 AM

    Essentially you needed to have finely tuned the policy enough such that no events or very little events are logged in normal running.  If you're getting thousands and thousands of events then the policy is noway near ready for production.



  • 5.  RE: Symantec Data Center Security: How do you confirm an intrusion

    Posted Aug 20, 2014 08:01 AM

    yes u have to fine tune the policy and also you can use search feature in DCS  server console which helps to identify the intrusion detection 



  • 6.  RE: Symantec Data Center Security: How do you confirm an intrusion

    Posted Aug 29, 2014 01:59 PM

    Anyone aware of training options for DCS - don't see anything avalaible from Symantec.

     

    http://www.symantec.com/products-solutions/training/theme.jsp?themeid=courses



  • 7.  RE: Symantec Data Center Security: How do you confirm an intrusion

    Posted Sep 01, 2014 03:48 AM

    DCS training is quite few and far between.  I suggest contacting a training partner of Symantec, as they can arrange DCS training for you, as training for this product is usually reserved for partners.