Table B-3
Message events that are sent to the Information Manager
(continued)
Rule
Description
(Reason sent)
Event class
Severity
Event ID
(SES_EVENT_<Unique ID>)
Spam message
symc_data_incident
Informational
SES_EVENT_SPAM_CONTENT
(132001)
Suspect Spam
message
symc_data_incident
Informational
SES_EVENT_GENERIC_CONTENT
(132000)
Content
violation
message
symc_data_incident
Informational
SES_EVENT_SENSITIVE_CONTENT
_ VIOLATION (182000)
Encrypted
message
symc_data_incident
Informational
SES_EVENT_GENERIC_CONTENT
(132000)
Administration events that are sent to the Information Manager
Table B-4
lists the administration events that Symantec Mail Security for SMTP
can send to the Information Manager.
Table B-4
Administration events that are sent to the Information Manager
Rule
Description
(Reason
sent)
Event class
Severity
Event ID
(SES_EVENT_<Unique ID>)
Registration
success
symc_config_update
Informational
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Registration
failure
symc_config_update
Warning
SES_EVENT_CONFIGURATION_FAILED
(92058)
BCC/service
stopping
symc_base
Informational
SES_EVENT_APPLICATION_STOP
(92002)
BCC/service
starting
symc_base
Informational
SES_EVENT_APPLICATION_START
(92001)
User login
successful
symc_host_intrusion
Informational
SES_EVENT_HOST_INTRUSION
(1032000)
User logout
successful
symc_host_intrusion
Informational
SES_EVENT_HOST_INTRUSION
(1032000)
61
Integrating Symantec Mail Security with Symantec Security Information Manager
Interpreting events in the Information Manager