DLP_security,
This is one of those things that people have been asking for a long time.. even myself a seasoned DLP expert.
There is an internal variable that has this information: $date-detected$
You can try and see if this will get populated in the SYSlog event that you send... try and see. I am not 100% sure it is available.
So one of the things I do is create a Custom Attribute (Event Date) that is then updated with the date the incident is created. Use the following script to do this and put it into a custom attribute field.
You can then POSSIBLY use this as a variable in the SYSlog or in an Email.. it will be &ATTRIBUTE_X$
you will need to find out what X is by highlighting the filed in an incident.. it will show up when you hover the mouse over a filled field.
The nice thing about this is that it also allows me to sort based on dates that are not the same format as what is in the UI.
You can put this into a VBS script.. or create another one.
' *******************************************************************************************************
' ****************************************** DLP Settings for Lookup ************************************
' *************************** script.1.command=C:/windows/system32/cscript.exe **************************
' ************** script.1.custom.args=/nologo,D:/SymantecDLP/protect/plugins/Hostlookup.vbs *************
' ********************************** stdin.filtering.enabled=true ***************************************
' ******************************** stdout.filtering.enabled=false ***************************************
' *******************************************************************************************************
Dim StdOut : Set StdOut = Wscript.Stdout
Dim objArgs : Set objArgs = WScript.Arguments
e=0
numArgs = objArgs.Count
dim attributeList
dim attributes
' *******************************************************************************************************
' ********** This section is required to parse out all of the attributes we may want to use ************
' ********** For the many parts of this script. It will ingest the attributes and give them ************
' ***************** an attribute value number, which will be referenced in the script. *****************
' *********** The numbers below are commented out so you can reference the number for each *************
' ************************* Attribute that is ingested along with their number **************************
' *******************************************************************************************************
' ******************* 0 ********** 1 ******* 2 *********** 3 ************* 4 *************** 5 **********
attributeList = ("sender-email,protocol,sender-ip,endpoint-user-name,date-detected,endpoint-machine-name")
attributes = split(attributeList,",")
Dim attributeValues(5)
' *******************************************************************************************************
' ************** This is a Loop to strip data right of the "=" for the attributes and it ****************
' ***** Assigns the attribute value for [x] attribute based on the attributes defined in the array *****
' *******************************************************************************************************
Do Until e = numArgs
strEqPos = Instr(objArgs(e),"=")
strArgName = mid(objArgs(e),1,strEqPos - 1)
strValLen = len(objArgs(e)) - strEqPos
strArgVal = mid(objArgs(e), strEqPos + 1, strValLen )
x=o
for each attribute in attributes
if strArgName = attribute then
attributeValues(x)=strArgVal
end if
x=x+1
next
e = e+ 1
Loop
v_mth=mid(attributeValues(4),5,3)
v_day=mid(attributeValues(4),9,2)
v_year=mid(attributeValues(4),25,4)
If v_mth = "Jan" Then
v_mthNum = "01"
ElseIf v_mth = "Feb" Then
v_mthNum = "02"
ElseIf v_mth = "Mar" Then
v_mthNum = "03"
ElseIf v_mth = "Apr" Then
v_mthNum = "04"
ElseIf v_mth = "May" Then
v_mthNum = "05"
ElseIf v_mth = "Jun" Then
v_mthNum = "06"
ElseIf v_mth = "Jul" Then
v_mthNum = "07"
ElseIf v_mth = "Aug" Then
v_mthNum = "08"
ElseIf v_mth = "Sep" Then
v_mthNum = "09"
ElseIf v_mth = "Oct" Then
v_mthNum = "10"
ElseIf v_mth = "Nov" Then
v_mthNum = "11"
ElseIf v_mth = "Dec" Then
v_mthNum = "12"
End If
' *******************************************************************************************************
' *********************************** format of YYYY-MM-DD. *********************************************
' ************************This format is best for sorting in the DLP UI. ********************************
' *******************************************************************************************************
stdOut.WriteLine "Event Date="&v_year&"-"&v_mthNum&"-"&v_day
' *******************************************************************************************************
' *********************************** format of MM-DD-YYYY **********************************************
' *******************************************************************************************************
'stdOut.WriteLine "Event Date="&v_mthNum&"-"&v_day&"-"&v_year
Please make sure to mark this as a solution to your problem, when possible.