Symantec 10744983 Administration Guide - Page 222

Interpreting events in the Information Manager, Symantec Security Information Manager documentation.

Page 222 highlights

222 Integrating Symantec Mail Security with Symantec Security Information Manager Interpreting events in the Information Manager Information Manager. The Information Manager provides you with an open, standards-based foundation for managing security events from Symantec clients, gateways, servers, and Web servers. SSIM Agents collect events from Symantec security products and send the events to the Symantec Security Information Manger which uses a sophisticated set of rules to filter, aggregate, and correlate the events into security incidents and allows for full tracking and response. The Symantec Security Information Manager allows you to manage and respond to incidents from threat and vulnerability from discovery through resolution. The Symantec Incident Manager evaluates the impact of incidents on the associated systems and assigns incident severities. A built-in Knowledge Base provides information about the vulnerabilities that are associated with the incident. The Knowledge Base also suggests tasks that you can assign to a help desk ticket for resolution. Symantec Security Information Manager is purchased and installed separately. The appliance must be installed and working properly before you can configure Symantec Mail Security to log events to the SSIM. For more information, see the Symantec Security Information Manager documentation. Interpreting events in the Information Manager SSIM provides extensive event management capabilities, such as common logging of normalized event data for Information Manager-enabled security products like Symantec Mail Security for SMTP. The event categories and classes include threats (such as viruses), security risks (such as adware and spyware), content filtering rule violations, network security, spam, and systems management. For more information about interpreting events in the Information Manager and on the event management capabilities of the Information Manager, see the Symantec Security Information Manager documentation. Symantec Mail Security for SMTP can send the following types of events to the Information Manager: ■ Firewall events ■ Definition Update events ■ Message events ■ Administration events

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249

Information Manager. The Information Manager provides you with an open,
standards-based foundation for managing security events from Symantec clients,
gateways, servers, and Web servers.
SSIM Agents collect events from Symantec security products and send the events
to the Symantec Security Information Manger which uses a sophisticated set of
rules to filter, aggregate, and correlate the events into security incidents and
allows for full tracking and response. The Symantec Security Information Manager
allows you to manage and respond to incidents from threat and vulnerability from
discovery through resolution.
The Symantec Incident Manager evaluates the impact of incidents on the
associated systems and assigns incident severities. A built-in Knowledge Base
provides information about the vulnerabilities that are associated with the incident.
The Knowledge Base also suggests tasks that you can assign to a help desk ticket
for resolution.
Symantec Security Information Manager is purchased and installed separately.
The appliance must be installed and working properly before you can configure
Symantec Mail Security to log events to the SSIM.
For more information, see the Symantec Security Information Manager
documentation.
Interpreting events in the Information Manager
SSIM provides extensive event management capabilities, such as common logging
of normalized event data for Information Manager-enabled security products like
Symantec Mail Security for SMTP. The event categories and classes include threats
(such as viruses), security risks (such as adware and spyware), content filtering
rule violations, network security, spam, and systems management.
For more information about interpreting events in the Information Manager and
on the event management capabilities of the Information Manager, see the
Symantec Security Information Manager documentation.
Symantec Mail Security for SMTP can send the following types of events to the
Information Manager:
Firewall events
Definition Update events
Message events
Administration events
Integrating Symantec Mail Security with Symantec Security Information Manager
Interpreting events in the Information Manager
222