Endpoint Protection

 View Only
  • 1.  SEPM ADC doesn't show parameter value

    Posted Jun 06, 2018 05:38 AM

    Good day dears,

     

    I've setup sepm v14 according to this article Using Application and Device Control in Symantec Endpoint Protection (SEP) to block activity in common loading points for threats - https://support.symantec.com/en_US/article.TECH96766.html and receive logs regarding the policy.

     

    But there is no parameter in the logs. Accordint to mentioned article:

    "Parameter: What was the process trying to touch? "

     

    How can I get this "parameter" shown in logs?

     

     

    Thank you in advance.



  • 2.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 06, 2018 11:29 AM

    There is a 'caller process' and 'target' field that should be reviewed.



  • 3.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 06, 2018 01:57 PM

    Thank you Brian,

     

    But how can I find (investigate) which file/registry value was created or written to by the "caller process" in the "target" directory?



  • 4.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 08, 2018 01:59 AM

    Guys any additional suggestions?



  • 5.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 09, 2018 02:52 AM

    This is very strange, because the mentioned parameter has been shown in the manual, but is absend in log



  • 6.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 09, 2018 07:41 AM

    Exact SEPM version is?

    May need to open a support case.



  • 7.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 11, 2018 03:44 PM

    SEPM version 14

     



  • 8.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 11, 2018 03:48 PM

    There are multiple versions of 14. Which one exactly?



  • 9.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 12, 2018 12:43 AM

    The exact version is Version 14.0.1 (14.0 RU1 MP1) build 3897 (14.0.3897.1101)



  • 10.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 13, 2018 02:42 AM

    Can the cause of the mentioned issue be the version of SEPM?



  • 11.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 15, 2018 12:56 PM

    Maybe a known issues fixed in 14.2, that was just released:

    http://www.symantec.com/docs/INFO5072

    ADC policy truncates log data

    Fix ID: 4131794

    Symptoms: An Application and Device Control log is missing data or truncates items that are expected to be there.

    Solution: Change Application Control log codes to only treat "*" as a special character if that description string came from internal codes.



  • 12.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 20, 2018 06:33 AM

    Thank you for your reply Brian!

     

    Update will take a time to implement. How can I "Change Application Control log codes to only treat "*" as a special character if that description string came from internal codes." as described in your post?

     

     



  • 13.  RE: SEPM ADC doesn't show parameter value

    Posted Jun 20, 2018 06:35 AM

    This was a fix in the latest release. Requires a product upgrade to implement.