Symantec 10268947 User Guide - Page 71

Annotating policies or events, Viewing policy annotations

Page 71 highlights

Protection Policies 71 Adjusting the view of event types automatically adds them to the policy. Even if the LiveUpdate occurs in the middle of the night, Symantec Network Security immediately starts logging the matching events. To view LiveUpdate 1 In the Policies tab, click Protection Policies > View > Auto Update Rules. 2 Click Cancel to close the view. Note: Both StandardUsers and RestrictedUsers can view Auto Update rules, but cannot add, edit, or delete them. Annotating policies or events You can take notes on events at the following three levels: ■ Viewing policy annotations ■ Viewing event type annotations ■ Annotating event instances Viewing policy annotations If notes were taken about a particular policy, then when you hover the cursor over that policy in the policy list, the note appears as a tool tip. To view a policy annotation ◆ In the Policies tab, hover the cursor over the policy to display the note as a tool tip. Note: Both StandardUsers and RestrictedUsers can view tool tips to protection policies, but cannot add, edit, or delete them. Viewing event type annotations The Network Security console provides a field in which to make notes about an event type within a policy. When the event is triggered, the note is displayed in the Event Details. For example, a note might indicate that this event is a false positive if it occurs within a certain IP range. The note is specific to that event type when it occurs in that policy. The Event Details pane displays the note each time this policy detects the annotated event.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

71
Protection Policies
Adjusting the view of event types
automatically adds them to the policy. Even if the LiveUpdate occurs in the
middle of the night, Symantec Network Security immediately starts logging the
matching events.
To view LiveUpdate
1
In the
Policies
tab, click
Protection Policies
>
View
>
Auto Update Rules
.
2
Click
Cancel
to close the view.
Note:
Both StandardUsers and RestrictedUsers can view Auto Update rules, but
cannot add, edit, or delete them.
Annotating policies or events
You can take notes on events at the following three levels:
Viewing policy annotations
Viewing event type annotations
Annotating event instances
Viewing policy annotations
If notes were taken about a particular policy, then when you hover the cursor
over that policy in the policy list, the note appears as a tool tip.
To view a policy annotation
In the
Policies
tab, hover the cursor over the policy to display the note as a
tool tip.
Note:
Both StandardUsers and RestrictedUsers can view tool tips to protection
policies, but cannot add, edit, or delete them.
Viewing event type annotations
The Network Security console provides a field in which to make notes about an
event type within a policy. When the event is triggered, the note is displayed in
the Event Details. For example, a note might indicate that this event is a false
positive if it occurs within a certain IP range. The note is specific to that event
type when it occurs in that policy. The Event Details pane displays the note each
time this policy detects the annotated event.