Symantec 10490452 Administration Guide - Page 228

Administration events that are sent to the Information Manager

Page 228 highlights

228 Integrating Symantec Mail Security with Symantec Security Information Manager Interpreting events in the Information Manager Administration events that are sent to the Information Manager Table C-7 lists the administration events that Symantec Mail Security for SMTP can send to the Information Manager. Table C-7 Administration events that are sent to the Information Manager Event ID (SES_EVENT_) Severity Event class Rule Description (Reason sent) SES_EVENT_CONFIGURATION_CHANGE (92008) Informational symc_config_update Registration success SES_EVENT_CONFIGURATION_FAILED (92058) Warning symc_config_update Registration failure SES_EVENT_APPLICATION_STOP (92002) Informational symc_base BCC/service stopping SES_EVENT_APPLICATION_START (92001) Informational symc_base BCC/service starting SES_EVENT_HOST_INTRUSION (1032000) Informational symc_host_intrusion User login successful SES_EVENT_HOST_INTRUSION (1032000) Informational symc_host_intrusion User logout successful SES_EVENT_HOST_INTRUSION (1032000) Warning symc_host_intrusion User login failed SES_EVENT_CONFIGURATION_CHANGE (92008) Informational symc_config_update Enable/add host SES_EVENT_CONFIGURATION_CHANGE (92008) Informational symc_config_update Disable/remove host SES_EVENT_HOST_INTRUSION (1032000) Minor symc_host_intrusion Prohibited action SES_EVENT_CONFIGURATION_CHANGE (92008) Informational symc_config_update Delete all SES_EVENT_CONFIGURATION_CHANGE (92008) Informational symc_config_update Change group policy SES_EVENT_LIST_UPDATE_FAILED (92059) Minor symc_defupdate Antispam filters old SES_EVENT_VIRUS_DEFINITION_UPDATE_FAI Major LED (92054) symc_defupdate Antivirus filters old SES_EVENT_LIST_UPDATE_FAILED (92059) Critical symc_defupdate Antispam license expired SES_EVENT_VIRUS_DEFINITION_UPDATE_FAI Critical LED (92054) symc_defupdate Antivirus license expired SES_EVENT_CONFIGURATION_CHANGE (92008) Informational symc_config_update Certificate imported

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258

228
Integrating Symantec Mail Security with Symantec Security Information Manager
Interpreting events in the Information Manager
Administration events that are sent to the Information Manager
Table C-7
lists the administration events that Symantec Mail Security for SMTP
can send to the Information Manager.
Table C-7
Administration events that are sent to the Information Manager
Event ID
(SES_EVENT_<Unique ID>)
Severity
Event class
Rule Description
(Reason sent)
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational
symc_config_update
Registration success
SES_EVENT_CONFIGURATION_FAILED (92058)
Warning
symc_config_update
Registration failure
SES_EVENT_APPLICATION_STOP (92002)
Informational
symc_base
BCC/service stopping
SES_EVENT_APPLICATION_START (92001)
Informational
symc_base
BCC/service starting
SES_EVENT_HOST_INTRUSION (1032000)
Informational
symc_host_intrusion
User login successful
SES_EVENT_HOST_INTRUSION (1032000)
Informational
symc_host_intrusion
User logout successful
SES_EVENT_HOST_INTRUSION (1032000)
Warning
symc_host_intrusion
User login failed
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational
symc_config_update
Enable/add host
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational
symc_config_update
Disable/remove host
SES_EVENT_HOST_INTRUSION (1032000)
Minor
symc_host_intrusion
Prohibited action
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational
symc_config_update
Delete all
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational
symc_config_update
Change group policy
SES_EVENT_LIST_UPDATE_FAILED (92059)
Minor
symc_defupdate
Antispam filters old
SES_EVENT_VIRUS_DEFINITION_UPDATE_FAI
LED (92054)
Major
symc_defupdate
Antivirus filters old
SES_EVENT_LIST_UPDATE_FAILED (92059)
Critical
symc_defupdate
Antispam license
expired
SES_EVENT_VIRUS_DEFINITION_UPDATE_FAI
LED (92054)
Critical
symc_defupdate
Antivirus license
expired
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational
symc_config_update
Certificate imported