- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Anti-virus signature not found
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anti-virus signature not found
We have logs indicating an anti-virus signature detected something, but didn't prevent it.
I want to change the action to drop, but I can't find the signature
What am I doing wrong?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Was starting to suspect this was a cloud-based detection of something new for which no signature had been propagated yet, but as it turns out you can't find it in the SmartConsole now because it has been removed in an update, from the ThreatWiki:
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Need to see the full log card for this log entry with IP addresses redacted.
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
attached
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please fully expose (with redaction as needed) all areas of the log card that have a caret "^" pointing downwards. Can't even tell if it is Anti-bot or Anti-virus with that screenshot.
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
anti-virus
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would suggest to change all detect to prevent - its the same resources spent but no action taken (except a log) with detect.
But better contact TAC about this...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
that's what I want to do, but I can't find the protection to make that change
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Was starting to suspect this was a cloud-based detection of something new for which no signature had been propagated yet, but as it turns out you can't find it in the SmartConsole now because it has been removed in an update, from the ThreatWiki:
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OK, thanks
