04.03.2013 Views

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

To modify the content of the notification message:<br />

PATH: NOTIFICATIONS > CLIENT USER NOTIFICATIONS<br />

1. Click the Behavior Monitoring Policy Violations tab.<br />

2. Modify the default message in the text box provided.<br />

3. Click Save.<br />

Behavior Monitoring Logs<br />

Using Behavior Monitoring<br />

Clients log unauthorized program access instances and send the logs to the server. A<br />

client that runs continuously aggregates the logs and sends them at specified intervals,<br />

which is every 60 minutes by default.<br />

To keep the size of logs from occupying too much space on the hard disk, manually<br />

delete logs or configure a log deletion schedule. For more information about managing<br />

logs, see Managing Logs on page 12-30.<br />

To view Behavior Monitoring logs:<br />

PATH: LOGS > NETWORKED COMPUTER LOGS > SECURITY RISKS<br />

NETWORKED COMPUTERS > CLIENT MANAGEMENT<br />

1. In the client tree, click the root domain icon<br />

specific domains or clients.<br />

to include all clients or select<br />

2. Click Logs > Behavior Monitoring Logs or View Logs > Behavior Monitoring<br />

Logs.<br />

3. Specify the log criteria and then click Display Logs.<br />

4. View logs. Logs contain the following information:<br />

• Date/Time unauthorized process was detected<br />

• Computer where unauthorized process was detected<br />

• Computer’s domain<br />

• Violation, which is the event monitoring rule violated by the process<br />

• Action performed when violation was detected<br />

• Event, which is the type of object accessed by the program<br />

7-11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!