
Table B-4
Administration events that are sent to the Information Manager
(continued)
Rule
Description
(Reason
sent)
Event class
Severity
Event ID
(SES_EVENT_<Unique ID>)
Sender
group
members
imported
symc_config_update
Informational
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Group
policy
members
imported
symc_config_update
Informational
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Component
is not active
symc_config_update
Informational
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Administrator
account
change
symc_config_update
Informational
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Virus
outbreak
symc_config_update
Major
SES_EVENT_VIRUS (122000)
Installing and configuring event logging to the
Information Manager
The logging of events to the Information Manager is in addition to, and
independent of, the logging of events within the Symantec Mail Security for SMTP
logging feature.
To configure logging to the Information Manager, you must complete the following
steps:
63
Integrating Symantec Mail Security with Symantec Security Information Manager
Installing and configuring event logging to the Information Manager