Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

Responce rule need filter of successfully executed

Created: 02 Mar 2012 | 2 comments
kishorilal1986's picture
0 Agree
0 Disagree
0 0 Votes
Login to vote

Hi guys,

This idea came in mind while I was executing responce rule for auto escalation.

  • I suggest / recommend to symantec to include this filter to sort out for which incidents responce rule is executed.
  • As we manually executing preconfigure response rules for automated escalation alert mail but when we apply for group of incidents then it is difficult to find out which is successfully executed and which is not.
  • For this currently we are checking individually incidents for sucessful mesage sent.

Thanks & Regards

Kishorilal

Comments 2 CommentsJump to latest comment

DLP Solutions2's picture

Kishorilal,

What you can do as part of the Response Rule is to alo have it update or edit a Custom Attribute field that says, "executed" or somthing like that.

You can then filter using that field to see what was run or not.

Please make sure to mark this as a solution

to your problem, when possible.

+2
Login to vote
Keith Reynolds - ExchangeTek's picture

The above is the way to go...I typically include a custom attribute called "User Notified" and "Manager Notified", and set this value to "Yes" when the response rule is executed.  It's great for reporting as well, as I can now tell, by user and policy, how many times a particular user has been notified.

~Keith

0
Login to vote