Prevent Info-Level "Application and Device Control is ready" events from triggering Notifications
When creating a Security Event notification in the Symantec Endpoint Protection Manager for "Application Control" events in the network, there are a lot of "False Positive" alerts created.
Every time a SEP client computer with Application and Device Control starts, the Sysplant component logs an event: "Application and Device Control is ready." These normal/expected events are still counted by the SEPM when determining whether to raise an alert or not. In my network, I received an alarming email "Security Alert by Number of Attacked Computers" even though the only activity was healthy SEP clients booting up in the morning.
If the SEPM's "What Settings Would You Like for this Notification?" configuration options allowed for the exclusion of "Info" level events, considering only "Minor" severity and above when determining if a notification should be triggered, that would prevent all of these alert mails when there was in fact nothing to worry about.
Alternate solution: allow admins to configure what ADC detections/events are forwarded from the clients to the SEPM. For AV and Firewall detections/events, admins can configure what events are logged and forwarded to the SEPMs (and able to trigger notifications) but this is not the case in the ADC policy.
Comments
Good idea, I fully agree.
Good idea, I fully agree. There should be more flexibility in configuring ADC alerts
What are the Symantec Endpoint Protection (SEP) versions released officially?
https://www-secure.symantec.com/connect/articles/w...
Fully Agree!!
We would LOVE to see this change. We are being flooded with useless alerts......
I have created the same idea:
https://www-secure.symantec.com/connect/ideas/sepm-application-and-device-control-notifications
Great idea!
We just upgraded to 12.1 and have been getting these false positives quite a bit. I would love to see this feature added in a future release to SEP.
Yes great idea, just had a
Yes great idea, just had a customer requesting the very same functionality.
Would you like to reply?
Login or Register to post your comment.