8-4
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 8 Configuring Antivirus Devices
Symantec AntiVirus Configuration
Figure 8-5
Symantec AV Action Msg
The following mandatary fields are required for MARS to parse AV traps. If these fields are among those
possible, you must define these fields in order before defining any of the optional fields.
•
Alert: <
Alert Name
>
•
Computer: <
Computer Name
>
•
Date: <
Date
>
•
Time: <
Time
>
•
Action: <
Actual Action
>
•
Description: <
Description
>
Note
This ordering is required is because some optional fields can be so long as to prevent Mars from correctly
parsing the mandatory fields if they do not appear first in the list of attributes.
The following optional fields can be defined after all mandatory fields are defined:
•
User: <
User
>
•
Virus Name: <
Virus Name
>
•
File Path: <
File Path
>
•
Severity: <
Severity
>
•
Source: <
Source
>
The following list identifies the trap type and the full list of possible fields:
Alert: Virus Found