Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Notifications need to state what type of scan triggered the incident

Created: 10 Sep 2009
timaa's picture
5 Agree
0 Disagree
+5 5 Votes
Login to vote

The way we handle incidents with SCS had a workflow where, if auto protect caught the problem the machine was looked at but with less urgency. If a machine detected a trojan via a scheduled scan, we took it that the machine was comprimised and the machine needed to be removed from the network and looked at immediately.

The alerts with SEP do not state which type of scan triggered the notification:
realtime
startup
scheduled
manual
...

The SEP notificaitons need to be able to state what type of scan triggered the notification