SYSTEM Username in Risk logs
Created: 20 Sep 2012 | 17 comments
Our risk log indicates SYSTEM as username for risks detected. We noticed that it was found on manual scan, scheduled scan and auto-protect detections.
What condition does the username SYSTEM appears during these detections?
Discussion Filed Under:
Comments 17 Comments • Jump to latest comment
hi,
Check this thread
http://www.symantec.com/connect/forums/system-account-sep-risk-logs
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi Ashish,
expected as scheduled scan is defined by admin/user and when threat detects the it shows user logged in. AV is running with system account however the demand scans will trigger the user logged profile and displays the threat detcted while user logged in.
Auto protect is the services and is of system account so when threat is detected it is still running as SYSTEM account and hence it shows the threat detected as SYSTEM.
The thread somehow did not clarify the following from our logs:
1. Manual scan (demand scan) shows SYSTEM when such scans should be triggered by a logged on user. Other detections on my logs shows the various usernames.
2. Schedule scan detections shows various usernames and SYSTEM.
3. Auto-protect detections also various usernames and SYSTEM.
Is there a condition on which the SYSTEM username reflected on the logs and not the user who is logged in?
HI,
What sepm version are you using ?
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
11 ru7
Symantec Endpoint Protection detected Risks while you were logged out," but there is nothing in the risk log
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi Ashish,
Thank you but I do not think this will apply on my case. We do have the detection logs but we could seem to know why SYSTEM username is reflected and what circumstances that it happens.
Hi,
Check this thread may be help.
http://www.symantec.com/connect/forums/symantec-endpoint-protection-detected-risks-while-you-were-logged-out
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
From what I've seen:
If no one is logged in, SYSTEM will show in logs.
If someone is logged in, they will show in logs.
SEP Knowledge Base
Endpoint SWAT
can you post the scan log and risk log?
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
Hi Pete,
Below sample from the risk logs (less some columns):
HI,
If some one not logged - System account showing in risk log.
Because Symantec services will be run system account
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi Ashish,
I would likey agree with you on this during scheduled scan and no one is logged in to the machine that would show as SYSTEM.
But cases were the detection was from Auto-Protect and Manual scan and the username is SYSTEM, are there circumstances that no user is logged in but SEP client triggers a detection from a manual or auto-protect scan?
As my logs are showing such cases, I just wanted to confirm if I also have interpreted them correctly.
Thank you.
Hi,
If process is initiated from the system itself then it will be logged as a SYSTEM. There are many processes which will be initiated by system itself.
If process is initiated by any user then that particular username will be logged.
Screenshot is attached to the reference.
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
Hi Chetan,
Below are sample of my detections in my risk logs (less other columns). Our environment is strictly only C: local drive. All of these detections are from external hard drives.
I believe below are not system processes and auto-scan are triggered only once file is accessed. Manual scan can only be trigger with logged on user. Did I missed anything?
You can initiate a manual scan from SEPM so the user doesn't have to be logged in.
SEP Knowledge Base
Endpoint SWAT
Hi,
I think auto run is enabled.
If auto run is enabled then it auto execute itself & at that time Symantec detects it.
It exectues itself using system account.
Make sure you follow Symantec best practice guide to protect the network.
http://www.symantec.com/docs/TECH105236
Microsoft KB articles to disable Autorun
http://support.microsoft.com/kb/967715
SEP 12.1 onwards auto run is by default disabled.
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
hi,
Some service are depend on system account. if anyone runing this services showing system name.
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Would you like to reply?
Login or Register to post your comment.