2.3. ANTIVIRUS
These log messages refer to the ANTIVIRUS (Anti-Virus related events) category.
2.3.1. virus_found (ID: 05800001)
Default Severity
Log Message
Virus found in file <filename>. Virus Name: <virusname>. Signature:
<virussig>. Advisory ID: <advisoryid>.
Explanation
A virus has been detected in a data stream. Since anti-virus is
running in protect mode, the data transfer will be aborted in order
to protect the receiver.
Gateway Action
block_data
Recommended Action
If the infected file is local, run anti-virus program to clean the file.
Revision
2
Parameters
filename
virusname
virussig
advisoryid
[layer7_srcinfo]
[layer7_dstinfo]
Context Parameters
ALG Module Name
ALG Session ID
Connection
2.3.2. virus_found (ID: 05800002)
Default Severity
Log Message
Virus found in file <filename>. Virus Name: <virusname>. Signature:
<virussig>. Advisory ID: <advisoryid>.
Explanation
A virus has been detected in a data stream. Since anti-virus is
running in audit mode, the data transfer will be allowed to continue.
Gateway Action
allow_data
Recommended Action
If the infected file is local, run anti-virus program to clean the file.
Revision
2
Parameters
filename
virusname
virussig
advisoryid
[layer7_srcinfo]
[layer7_dstinfo]
Context Parameters
Chapter 2: Log Message Reference
171
Summary of Contents for NetDefend DFL-260E
Page 32: ...List of Tables 1 Abbreviations 35 32...
Page 33: ...List of Examples 1 Log Message Parameters 34 2 Conditional Log Message Parameters 34 33...
Page 42: ...routemetric Route metric cost Chapter 1 Introduction 42...
Page 44: ...Chapter 1 Introduction 44...
Page 216: ...Rule Information Connection Chapter 2 Log Message Reference 216...
Page 243: ...client_ip Context Parameters Rule Name Packet Buffer Chapter 2 Log Message Reference 243...
Page 556: ...logger Chapter 2 Log Message Reference 556...
Page 613: ...Parameters location Chapter 2 Log Message Reference 613...