228 Integrating Symantec Mail Security with Symantec Security Information Manager
Interpreting events in the Information Manager
Administration events that are sent to the Information Manager
Table C-7
lists the administration events that Symantec Mail Security for SMTP
can send to the Information Manager.
Table C-7
Administration events that are sent to the Information Manager
Event ID
(SES_EVENT_<Unique ID>)
Severity
Event class
Rule Description
(Reason sent)
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational symc_config_update
Registration success
SES_EVENT_CONFIGURATION_FAILED (92058) Warning
symc_config_update
Registration failure
SES_EVENT_APPLICATION_STOP (92002)
Informational symc_base
BCC/service stopping
SES_EVENT_APPLICATION_START (92001)
Informational symc_base
BCC/service starting
SES_EVENT_HOST_INTRUSION (1032000)
Informational symc_host_intrusion
User login successful
SES_EVENT_HOST_INTRUSION (1032000)
Informational symc_host_intrusion
User logout successful
SES_EVENT_HOST_INTRUSION (1032000)
Warning
symc_host_intrusion
User login failed
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational symc_config_update
Enable/add host
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational symc_config_update
Disable/remove host
SES_EVENT_HOST_INTRUSION (1032000)
Minor
symc_host_intrusion
Prohibited action
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational symc_config_update
Delete all
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational symc_config_update
Change group policy
SES_EVENT_LIST_UPDATE_FAILED (92059)
Minor
symc_defupdate
Antispam filters old
SES_EVENT_VIRUS_DEFINITION_UPDATE_FAI
LED (92054)
Major
symc_defupdate
Antivirus filters old
SES_EVENT_LIST_UPDATE_FAILED (92059)
Critical
symc_defupdate
Antispam license
expired
SES_EVENT_VIRUS_DEFINITION_UPDATE_FAI
LED (92054)
Critical
symc_defupdate
Antivirus license
expired
SES_EVENT_CONFIGURATION_CHANGE
(92008)
Informational symc_config_update
Certificate imported
Содержание Mail Security
Страница 1: ...Symantec Mail Security for SMTP Administration Guide ...
Страница 16: ...16 About Symantec Mail Security for SMTP Where to get more information ...
Страница 60: ...60 Configuring email settings Configuring scanning settings ...
Страница 116: ...116 Configuring email filtering Managing policy resources ...
Страница 142: ...142 Working with Spam Quarantine Configuring Spam Quarantine ...
Страница 150: ...150 Working with Suspect Virus Quarantine Configuring Suspect Virus Quarantine ...
Страница 162: ...162 Configuring alerts and logs Configuring logs ...
Страница 208: ...208 Feature Cross Reference About email filtering and message handling options ...