- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Symantec DLP 10.x
With the 10.0 update to Symantec DLP (formerly Vontu) you can syslog a relevant amount of information about detected events. I have attached a VERY small XML to add with the instructions below. I have to assume you are aware of how to create policies and a syslog response rule in DLP to keep this explanation short.
For my XML to work your syslog string needs to be:
BLOCKED|unknown|INCIDENT_ID|$INCIDENT_ID$|RECIPIENTS|$RECIPIENTS$|SENDER|$SENDER$|RULES|$RULES$|SEVERITY|Unknown|MATCH_COUNT|$MATCH_COUNT$|POLICY|$POLICY$|SUBJECT|$SUBJECT$|FILE_NAME|$FILE_NAME$|PARENT_PATH|$PARENT_PATH$|PATH|$PATH$|QUARANTINE_PARENT_PATH|$QUARANTINE_PARENT_PATH$|SCAN|$SCAN$|TARGET|$TARGET$
The general format of the message is PARAMETER|VALUE. You will notice some have hardcoded values. This is an unfortunate issue with DLP 10.0 that causes the syslog sender to crash if you supply a variable for the blocked or severity parameters. Look for that to be fixed soon if not already in 10.5.
I also removed the parameter supplying a url to the specific incident as that is relatively useless from within envision and takes up space in the IPDB. Don't worry the incident ID is parsed into the POLICYID field. Word of Advice: keep your policy and rule names short and meaningful if you want your envision reports to look nice. Try REGS-PCI, REGS-GLBA, RULE-CUSTDATA, RULE-IP
I will add some work on the system-generated messages as time goes on.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
All,
We are more than happy to build the integration parser to support Vontu but we are not able to get necessary logs and details (Symantec is not cooperating, I can imagine why :-))
Any body who can help us in this regard please let me know...as soon as we have sufficient logs, we will build a supported parser,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Please ping me about this next week and I will supply a washed version for your efforts. -C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
great news. we will ping you next week.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
In your mailbox.
