V 2.0 : SEP General Agent System Messages

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

N/A

<severity>

<severity>

N/A

N/A

<tag1>

N/A

<dname>

<dname>

N/A

N/A

<subject>

N/A

N/A

<tag2>

N/A

<process>

N/A

N/A

<version>

N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1000436

Virus Definitions Loaded

Base Rule

New Virus Definitions Loaded

Other Audit Success

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1011168

V 2.0 : SEP General Agent System Messages

Base Rule

General System Information

Information

V 2.0 : SEP Agent General Error Message

Sub Rule

General System Error

Error

V 2.0 : SEP Agent General Warning Message

Sub Rule

General System Warning

Warning

V 2.0 : SEP Agent General Information Message

Sub Rule

General System Information

Information

V 2.0 : SEP Agent LiveUpdate Encountered Errors

Sub Rule

General LiveUpdate Error

Error

V 2.0 : SEP Agent LiveUpdate Cancelled

Sub Rule

General LiveUpdate Warning

Warning

V 2.0 : SEP Agent Content Update Failed

Sub Rule

Update Failure

Error

V 2.0 : SEP Agent General Critical Message

Sub Rule

General System Critical

Critical

V 2.0 : SEP Agent Version Information

Sub Rule

General Version Information

Information

V 2.0 : SEP Info Submission To Symantec Fail

Sub Rule

File Upload Failed

Error

V 2.0 : SEP File Info Submission To Symantec

Sub Rule

File Upload Failed

Error

V 2.0 : SEP File Submission To Symantec Failed

Sub Rule

File Upload Failed

Error

V 2.0 : SEP Agent LiveUpdate Succeeded

Sub Rule

LiveUpdate Suceeded

Information

V 2.0 : SEP Agent Content Update Succeeded

Sub Rule

Update Complete

Information

V 2.0 : SEP Process Already Running

Sub Rule

Process Is Already Running

Warning

V 2.0 : SEP File Info Submission To Symantec

Sub Rule

File Uploaded

Information

V 2.0 : SEP File Submission To Symantec Succeeded

Sub Rule

File Uploaded

Information