Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

SSIM - Symantec Endpoint Protection Event Collector - Selective Event Forwarding

Created: 24 Nov 2009 | 1 comment
DP01's picture
0 Agree
0 Disagree
0 0 Votes
Login to vote

In a multi-site SEPM environment, where logs are forwarded to a SEP Management Site and SSIM SEP Event Collectors are installed on the non SEP Management sites, you currently can not run a SSIM SEP Event Collector on the SEP Management site, otherwise duplicate events  would be forwarded to SSIM. This currently prevents the forwarding of any events from any clients that are currently managed by the SEP Management site.

Proposal - The SSIM SEP Event Collector be configurable to only forward those events that have been generated on that site and not forward any events from any other site that may be configured to forward logs to it.

Comments

BadBoo's picture
25
Nov
2009
0 Votes 0
Login to vote

Create a filter

You can try creating a filter specification with a condition "originating_site" not equal to "<your site>" and enable it. This should prevent colelctor from getting information about other sites' activity.

Thanks,

Alexey.