Endpoint Protection

 View Only
  • 1.  Query : Email Notification of configuration of Risk events [not Reports]

    Posted Sep 15, 2016 06:25 AM

    Hello,

    The SEPM has 2 main groups for server-class systems.

    These 2 groups contain a good number of sub-groups - approximately 50 sub-groups.

    If the formats of these groups and sub-groups are "My Company\Server-Group" and "My Company\Server-Group\Sub-Group" respectively, the entire bunch of sub-groups do not fit in 1 'Notification Condition'. In our case, it has gone up to 8 conditions, which is an administrative overhead.

    Does SEPM honour wildcard entries such that all sub-groups within main groups A and B along with the 2 main groups themselves are monitored for "Notification Conditions"?

    The Help section in SEPM console mentions the following, but the explanation in the example is not clear.

    -----------------------------

    Specifies the group in which you want the conditions that you set to trigger the notification.

    This field accepts a comma-separated list as input. You can use the wildcard character question mark (?), which matches any one character, and the asterisk (*), which matches any string of characters. You can also click the dots to select from a list of known groups.

    Note:

    All groups are subgroups of the default parent group. When this filter searches for groups, it searches hierarchically starting with the name of the default group. Unless the name of your group starts with the same letter, you should precede the search string with an asterisk when using wildcards.

    For example, if you have a group named Purchasing, and you type p* into this box, no group is found and used in the view. To find a group named Purchasing, you need to use *p* instead.

     

    -----------------------------

    1. Will placing an asterisk after the main group, as seen below, send email notifications for all sub-groups?

    • "My Company\Server-GroupA"
    • "My Company\Server-GroupA\*"
    • "My Company\Server-GroupB"
    • "My Company\Server-GroupB\*"

     

    2. Secondly, can the same information be sent as an attachment in the email notification?

     

    Thanks,

    Jimmy

    =-=-=



  • 2.  RE: Query : Email Notification of configuration of Risk events [not Reports]
    Best Answer

    Posted Sep 15, 2016 07:47 AM

    It should look like this:

    • My Company\Server-GroupA*
    • My Company\Server-GroupB*

    Attachments are not supported for the alerts.



  • 3.  RE: Query : Email Notification of configuration of Risk events [not Reports]

    Posted Sep 15, 2016 09:57 AM

    Thanks Brian for the quick revert!

    I could successfully test notification for sub-groups.

    Is Symantec working on sending the information as attachment for Risks the way it is done for Reports?

     

    -Jimmy

    =-=-=



  • 4.  RE: Query : Email Notification of configuration of Risk events [not Reports]

    Posted Sep 15, 2016 10:04 AM

    Product enhancement requests have been made in the past but I have not seen it implemented.