Top source of attacks shows Zero
Updated: 03 Sep 2010 | 13 comments
This issue has been solved. See solution.
The console shows that we have some attacks in our network ( and I am sure we have some), however the report shows the number of attacks zero.
What can be the issue?
We have
Almost 2000 Clients
3 SEPM server
DB is SQL 2005
We have recently upgraded to MR6 and we didn't have the issue before the upgrade.
Discussion Filed Under:
Comments
hi
i think you should create a report for attacks than top source of attacks
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Maybe this report clarifies more
Symantec Certified Specialist \ MCSE +Security \ CCNSP
Rafeeq
would you plz explan more. What should I exactly do?
Symantec Certified Specialist \ MCSE +Security \ CCNSP
any hint?
Symantec Certified Specialist \ MCSE +Security \ CCNSP
Restart SEPM service once and try to create reports again....
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
I restarted the SEPM services, but didn't work.
Another point is that the Attacks graph in the Home section disapears and shows a cross something like can't open picture.
Symantec Certified Specialist \ MCSE +Security \ CCNSP
Enter subject (optional)
Can you provide us a screen shot...
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
The screen shot
Symantec Certified Specialist \ MCSE +Security \ CCNSP
Surprise!!!
Eventually the graph comes up with no issue! But it disappears sometimes!
Come on! That is crazy!
Alright, let me summarize:
Symantec Certified Specialist \ MCSE +Security \ CCNSP
Do you tried by removing IE enhanced security?
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Are you remotely accessing the SEPM???
Check the screen resoltuion it should be 32 bit. for clour quality.
Try this also
KB 935560
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
The reason that the Top Source of Attacks was ziro:
the IPS policy has a tick indicating whether the policy should be enabled or not. It was not checked!
Symantec Certified Specialist \ MCSE +Security \ CCNSP
Would you like to reply?
Login or Register to post your comment.