Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Prevent Info-Level "Application and Device Control is ready" events from triggering Notifications

Updated: 20 Oct 2011 | 4 comments
Mick2009's picture
11 Agree
1 Disagree
+10 12 Votes
Login to vote

When creating a Security Event notification in the Symantec Endpoint Protection Manager for "Application Control" events in the network, there are a lot of "False Positive" alerts created. 

Every time a SEP client computer with Application and Device Control starts, the Sysplant component logs an event: "Application and Device Control is ready."  These normal/expected events are still counted by the SEPM when determining whether to raise an alert or not.  In my network, I received an alarming email "Security Alert by Number of Attacked Computers" even though the only activity was healthy SEP clients booting up in the morning. 

If the SEPM's "What Settings Would You Like for this Notification?" configuration options allowed for the exclusion of "Info" level events, considering only "Minor" severity and above when determining if a notification should be triggered, that would prevent all of these alert mails when there was in fact nothing to worry about.

Alternate solution: allow admins to configure what ADC detections/events are forwarded from the clients to the SEPM.  For AV and Firewall detections/events, admins can configure what events are logged and forwarded to the SEPMs (and able to trigger notifications) but this is not the case in the ADC policy. 

Comments

w-d's picture
21
Oct
2011
3 Votes +3
Login to vote

Good idea, I fully agree.

Good idea, I fully agree. There should be more flexibility in configuring ADC alerts

What are the Symantec Endpoint Protection (SEP) versions released officially?
https://www-secure.symantec.com/connect/articles/w...

JWatts's picture
09
Nov
2011
3 Votes +3
Login to vote

Fully Agree!!

We would LOVE to see this change.  We are being flooded with useless alerts......

I have created the same idea:

https://www-secure.symantec.com/connect/ideas/sepm-application-and-device-control-notifications

Adrian Iwanczuk's picture
13
Dec
2011
3 Votes +3
Login to vote

Great idea!

We just upgraded to 12.1 and have been getting these false positives quite a bit.  I would love to see this feature added in a future release to SEP.

Neil74's picture
14
Feb
2012
2 Votes +2
Login to vote

Yes great idea, just had a

Yes great idea, just had a customer requesting the very same functionality.