Endpoint Protection

 View Only
Expand all | Collapse all

Multiple eMail notification when new risk is detected

Migration User

Migration UserJun 08, 2012 09:16 AM

kurt w

kurt wJul 03, 2012 05:37 AM

  • 1.  Multiple eMail notification when new risk is detected

    Posted Jun 08, 2012 05:15 AM

    Hello, since I upgrade SEPM from 12.1RU1 to 12.1RU1MP1, when client detect a nex risk I receive a mail to notifie me that a new risk has been detected and every 10 minutes I receive another mail. This is how is configure 'Notification' :

    Mails :

     

    What's wrong with this notification policy ?

     

    Thanks.



  • 2.  RE: Multiple eMail notification when new risk is detected

    Broadcom Employee
    Posted Jun 08, 2012 05:35 AM

    can you delete the policy and create a new one with same settings and let know if it fixes?



  • 3.  RE: Multiple eMail notification when new risk is detected

    Trusted Advisor
    Posted Jun 08, 2012 05:59 AM

    Hello,

    If the number of Single Risk Event notifications is small, removing/re-creating the notifications will resolve the issue.  This works because newly created notification conditions will include the time zone name value.

    Hope that helps!!



  • 4.  RE: Multiple eMail notification when new risk is detected

    Broadcom Employee
    Posted Jun 08, 2012 07:47 AM

    Hi Dcourtel,

    It's happening because damper protection setting is set to 'Auto'.

    Set the specific time setting and monitor the difference.

    I hope it will resolve your issue.



  • 5.  RE: Multiple eMail notification when new risk is detected

    Posted Jun 08, 2012 09:09 AM

    Hello pete, I delete and recreate the policy, and that doesn't fixe.



  • 6.  RE: Multiple eMail notification when new risk is detected

    Posted Jun 08, 2012 09:16 AM

    Did you tryed by changing the damper settings?



  • 7.  RE: Multiple eMail notification when new risk is detected

    Posted Jun 08, 2012 09:34 AM

    Trying with 20 minutes. I wait for the next virus :-)



  • 8.  RE: Multiple eMail notification when new risk is detected

    Posted Jun 08, 2012 09:43 AM

    You can use this for testing

    http://www.eicar.org/86-0-Intended-use.html

     

    :)



  • 9.  RE: Multiple eMail notification when new risk is detected

    Posted Jun 15, 2012 05:24 AM

    Hi Folks,

    same issue here. One Event creates 6 Notification being sent exactly every 10 minutes.

    I have a NEW SEP 12.1 RU1 MP1 Installation.

    Regards,

    Holger



  • 10.  RE: Multiple eMail notification when new risk is detected

    Posted Jun 15, 2012 05:53 AM

    Hello HolgerMu, edit the notification policy and set the "Damper" setting to 5 hours. It's very funny.



  • 11.  RE: Multiple eMail notification when new risk is detected

    Posted Jun 15, 2012 08:19 AM

    Setting the Damper Setting to 20 Minutes sends 2 Messages per Risk event within 10 minutes

    I assume 30 minutes sends 3 messages for 30 minutes and so on....

    5 Hours only sends 1 Message....funny funny stuff

     



  • 12.  RE: Multiple eMail notification when new risk is detected

    Posted Jul 03, 2012 05:37 AM

    any news about this Problem



  • 13.  RE: Multiple eMail notification when new risk is detected

    Posted Jul 05, 2012 01:49 PM

    We had this problem and this is what Symantec Enterprise Support had us do:

     

    "There may be a workaround. Try editing the conf.properties file located at Program Files (x86) \ Symantec \ Symantec Endpoint Protection Manager \ tomcat \ etc\

     

    Edit the line scm.securityalertnotifytask.notification.interval=1

    Change the 1 to 59."

     

    Our value was 10.. but after changing it to 59 as suggested the problem went away.



  • 14.  RE: Multiple eMail notification when new risk is detected

    Posted Jul 21, 2012 10:52 PM

     

     

     

     
    Multiple Symantec Endpoint Protection Manager email notifications are sent for old events
    http://www.symantec.com/docs/TECH144817

    Supplemental Materials

    Source ETrack
    Value 2212158
    Description

    SEP 12 SMB -- Multiple Risk Outbreak email notifications are sent within the Damper period


    Source ETrack
    Value 2233045
    Description

    SEP 11 RU6 MP2 --- SEPM email notifications sent repeatedly for old events

     

     Additional improvements are expected in the next release of SEP12.1



  • 15.  RE: Multiple eMail notification when new risk is detected

    Posted Aug 06, 2012 09:00 AM

    Having this stupid problem after upgrading SEPM to the latest version. Email every 10 minutes for the Virus definitions out-of-date alert. Deleting and re-creating the alert doesn't help.

    I'm running RU1, MP1. The article linked above states this is fixed in RU1?

     

    I had no problem with this on RU1. Stupid Symantec, fix one thing, break 10 other things as usual.



  • 16.  RE: Multiple eMail notification when new risk is detected

    Posted Aug 06, 2012 09:16 AM

    Please try the following.

    Delete the notification, wait for a day and then re-create the same notification.

     



  • 17.  RE: Multiple eMail notification when new risk is detected

    Posted Aug 06, 2012 09:20 AM

    why? 1 day is the magical number? why not two or three days?

     

    I'm trying the suggestion Muad'Dib has above. Hopefully it works, but who knows what else it's going to break?



  • 18.  RE: Multiple eMail notification when new risk is detected

    Posted Aug 06, 2012 01:09 PM

    When i spoke to Symantec Enterprise support about this they said yes they did fix it in RU1, but it appears that it became broken again in RU1MP1... lol



  • 19.  RE: Multiple eMail notification when new risk is detected

    Posted Aug 06, 2012 01:10 PM

    It works.. and the suggestion came directly from Enterprise Support. We havent experienced any fallout from the setting change. They did mention however when the next release is sent out that you should roll back this setting before updating.