Next Topic

Previous Topic

Book Contents

Alerts

The Antivirus module does not have its own alerts page. Instead Antivirus alerts are enabled on managed machines using the Monitor > Event Log Alerts page.

Antivirus Event Log Settings

Event log alerts have a prerequisite. The collection of the appropriate event log data from a managed machine must be enabled. Using the Agent > Event Log Settings page, select the following settings for each Antivirus managed machine you wish to configure alerts for:

Antivirus Event Log Alerts

On the Monitor > Event Log Alerts page select the Application event log type. When Antivirus is installed, the following predefined event sets can be assigned to a Antivirus managed machine.

The ZC-KAV prefix indicates that these event sets are sample Antivirus event sets. Sample event sets can be used directly or they can be used as examples for building your own Antivirus alert event sets. The next segment following ZC-KAV indicates the type of alert. The following are the Antivirus alert types:

If the number following the alert type designator is zero (0), the event set is a rollup of related alerts. Any number other than zero (0) indicates the event set is a single individual alert. The letters following the alert type segment indicate the event categories covered by the alert:

When configuring Antivirus alerts, ensure all three of the Error, Warning, and Information event categories are selected.

Also, for rollup event sets (ZC-KAV-DF0, ZC-KAV-FS0, ZC-KAV-QS0, or ZC-KAV-TH0), be sure to set the Ignore additional alarms for option to a low threshold, 1 minute, for example. This ensures that the multiple alerts possible in a rollup event set are not ignored if they should occur.