Skip to main content
Skip table of contents

Catch All - Symantec AntiVirus

Classification

Rule Name

Rule Type

Common Event

Classification

Catch All - Symantec AntiVirusBase RuleGeneral Symantec AntiVirus InformationInformation
EVID 2 : Scan CompleteSub RuleScan CompleteOther Audit Success
EVID 3 : Scan StartedSub RuleScan StartedInformation
EVID 6 : ErrorSub RuleAnti-Virus Error MessageError
EVID 7 : New Virus File DownloadedSub RuleFile DownloadInformation
EVID 12 : Symantec Endpoint ProtectionSub RuleGeneral Symantec AntiVirus InformationInformation
EVID 13 : Shutdown SuccessfulSub RuleSystem Startup Or Shutdown ActivityStartup and Shutdown
EVID 14 : Startup SuccessfulSub RuleSystem Startup Or Shutdown ActivityStartup and Shutdown
EVID 16 : New File Request SuccessfulSub RuleRequest ApprovedOther Audit Success
EVID 21 : Scan CancelledSub RuleScan CancelledWarning
EVID 40 :  Virus Definition MissingSub RuleVirus Definitions Are Not Up To DateWarning
EVID 45 : Security Risk DetectedSub RuleSuspicious Network ActivitySuspicious
EVID 51 : Security Risk DetectedSub RuleSuspicious ActivitySuspicious
EVID 65 : Scan SuspendedSub RuleScan StoppedInformation
EVID 66 : Scan ResumedSub RuleScan ResumedInformation
EVID 69 : Scan FailureSub RuleScan Failure - Password ProtectedWarning
EVID 80 : Download FailedSub RuleDownload Object FailureAccess Failure
EVID 34054 : SONAR EnabledSub RuleConfiguration Enabled : SystemConfiguration
EVID 34057Sub RuleConfiguration Enabled : SecurityConfiguration

Mapping with LogRhythm Schema  

Device Key in log message

LogRhythm Schema

Data Type

Provider Name<vendorinfo>Text/String
EventID Qualifiers<vmid>Number
Level<severity>Text/String
N/A<login>Text/String
N/A<domainorigin>Text/String
Computer<dname>Text/String
N/A<object>Text/String
N/A<objectname>Text/String
N/A<objecttype>Text/String
N/A<parentprocesspath>Text/String
N/A<command>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.