Critical System Protection

 View Only
  • 1.  SCSP Shutdown & Deleting the Collectors

    Posted Jun 05, 2014 01:45 AM
      |   view attached

    Hi,

    From Symantec Critical System Protection i attached error which detection logs where deleted for no reason

     

     



  • 2.  RE: SCSP Shutdown & Deleting the Collectors

    Posted Jun 05, 2014 04:01 PM

    The logs were deleted?  The actual .csv files on the endpoint?

    The sequence in your screenshot looks like the SISIDSService was shut down/stopped.

     



  • 3.  RE: SCSP Shutdown & Deleting the Collectors
    Best Answer

    Posted Jun 13, 2014 04:44 PM

    As Chuck mentioned those are CSP IDS "Collectors" which are responsible for such things as monitoring the registry, windows event logs, etc... These collectors do cache events in certain circumstances, specifically on very busy systems, likely these are snippets of events while the shutdown process of the executable is occuring. The "cache" is basically a FIFO (first in first out) scenario, as a sub process "sanity" checks the log or file message (event) before it is injected into the log files below, where it is then processed by logger.exe which eventually injects them into the CSP DB.

    If actual events were being deleted then you would see them removed from :\program files (x86)\symantec\ciritical system protection\agent\scsplogs\SISRTevents.csv or SISIDSevents.csv