Symantec 10490452 Administration Guide - Page 225

Configuring data sources, Settings for Message statistics

Page 225 highlights

Integrating Symantec Mail Security with Symantec Security Information Manager 225 Interpreting events in the Information Manager Note: Although some of the Information Manager Event IDs are the same for multiple events, the event descriptions and occasionally the severity is different. Configuring data sources You must configure the following data sources on the Information Manager to receive events from Symantec Mail Security for SMTP. You can add a new sensor for each data source. Once you have configured these sources, you must distribute the configuration to the Collector for it to take effect. For more information, refer to the Symantec Security Information Manager documentation. Table C-1 Settings for Message statistics Setting Value Type: Path for Linux/Solaris: Path for Windows: Filename: Configure as: Message stats /opt/Symantec/SMSSMTP/scanner/stats/ c:\Program Files\Symantec\SMSSMTP\scanner\stats\ bmi_eng_stats Monitor in Real Time Table C-2 Settings for Firewall statistics Setting Value Type: Path for Linux/Solaris: Path for Windows: Filename: Configure as: Firewall stats /opt/Symantec/SMSSMTP/scanner/stats/ c:\Program Files\Symantec\SMSSMTP\scanner\stats\ bmi_fw_stats Monitor in Real Time Table C-3 Settings for Administrative and Definition Update statistics Setting Value Type: Path for Linux/Solaris: Admin and Definition Update stats /opt/Symantec/SMSSMTP/logs/tomcat/BMI_SESA/ Brightmail_SESA_Events.2

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258

225
Integrating Symantec Mail Security with Symantec Security Information Manager
Interpreting events in the Information Manager
Note:
Although some of the Information Manager Event IDs are the same for
multiple events, the event descriptions and occasionally the severity is
different.
Configuring data sources
You must configure the following data sources on the Information Manager to
receive events from Symantec Mail Security for SMTP. You can add a new
sensor for each data source. Once you have configured these sources, you must
distribute the configuration to the Collector for it to take effect. For more
information, refer to the Symantec Security Information Manager
documentation.
Table C-1
Settings for Message statistics
Setting
Value
Type:
Message stats
Path for Linux/Solaris:
/opt/Symantec/SMSSMTP/scanner/stats/
Path for Windows:
c:\Program Files\Symantec\SMSSMTP\scanner\stats\
Filename:
bmi_eng_stats
Configure as:
Monitor in Real Time
Table C-2
Settings for Firewall statistics
Setting
Value
Type:
Firewall stats
Path for Linux/Solaris:
/opt/Symantec/SMSSMTP/scanner/stats/
Path for Windows:
c:\Program Files\Symantec\SMSSMTP\scanner\stats\
Filename:
bmi_fw_stats
Configure as:
Monitor in Real Time
Table C-3
Settings for Administrative and Definition Update statistics
Setting
Value
Type:
Admin and Definition Update stats
Path for Linux/Solaris:
/opt/Symantec/SMSSMTP/logs/tomcat/BMI_SESA/
Brightmail_SESA_Events.2