Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Real Time Notification from SEP

Updated: 12 Dec 2009 | 3 comments
serhi's picture
30 Agree
2 Disagree
+28 32 Votes
Login to vote
Status: Reviewed

The customers want real time notification from SEP when the risks are detected. In case SEP, we can receive the mail from SEP after a while and they are different from AMS in SAVCE.

Comments

peterc's picture
07
Sep
2009
1 Vote +1
Login to vote

Agree

A 20 minute damper (or more) is not very good when responding quickly to virus alerts can be the difference between a small invonvenience and a big problem.
The damper should be able to be set as low as 1 minute.

Jeremy Dundon's picture
08
Sep
2009
3 Votes +3
Login to vote

even if you set the damper to 1 minute

The clients still wait till their check-in time to send the log to the server, so you are already waiting for the amount of time that the client waits between checking in. (5 minutes by default) 

Gary Van Horn's picture
08
Sep
2009
5 Votes +5
Login to vote

I agree with Jeremy that,

I agree with Jeremy that, with a little configuration, the notification timeline can get as low as the client's check-in interval.

That said, real-time notification of risks (essentially a risk detection forcing a heartbeat) is something most people would find helpful when dealing with a new threat. It could change the scenario from one where many systems have to be cleaned to one where a small handful of systems are quickly quarantined.