New York Data Loss Prevention User Group

 View Only
  • 1.  SNMP trap / MIB for incident reporting to NMS

    Posted Apr 27, 2011 09:52 AM

    Client is using their 24x7 NOC/SOC to perform after-hours, priority SDLP incident triage -- and hoping to have Enforce dump over to their NMS via SNMP.

    Is there out-of-the-box support in the product? If not (and I'm assuming not, given what I've seen/read), has anyone coded something like this before?

    Thanks in advance,

    -Sean



  • 2.  RE: SNMP trap / MIB for incident reporting to NMS

    Posted Apr 27, 2011 02:26 PM

    Hi Sean -

    Hope all is well with you.  You're correct in your assumption...there's no OOTB support for SNMP.  I for one haven't coded anything to do this either, but I've done some research before for this.  There's a number of tools out there that claim to do Syslog to SNMP conversion.  My thought on this (if those tools work as advertised) is that you could easily set up a Syslog response rule that sends to that app, which would convert it to an SNMP event, and there you go.

    Not ideal in that it adds a layer there...but buying one of those tools might be a lot cheaper than trying to develop a customization, since you can use the OOTB Syslog response rule in DLP.

    Regards,

    ~Keith

     



  • 3.  RE: SNMP trap / MIB for incident reporting to NMS

    Posted Apr 28, 2011 11:46 AM

    A first, What data gets added to an Symantec security Information manager V4.5 SNMP trap?

    -Type- String value -Incident description from rule incident security TECH 85612

    -Veritas operation Manager  3.0(VOM) fixed incident list 2HM 1949421[cluster]: Blank pop-up window appears after probing resources 2cms 1949645 update the copyright year to 2010 through out the VOM 3.0 product 2CMS 1949736 [Rule Manager] SNMP trap is not working  2CMS

    - SNMP traps are truncated and are missing a final character when arriving at the dSNMP console,this incident is fixed in VCS5.1 RP1 and above.

    -Veritas storage foundation (tm) 4.1 for window fixed incident history 11221301 VSFW does not send the SNMP trap for a DMP path failure to the recipient.

    - Confuguring backup Exec System Recovery to send SNMP traps.

    -If you use network Management System (NMS) application yopu can configure backup exe system recovery to send SNMP trap for different priority and notification types.

    -White paper Template, when Potential problems arise automated recovery actions can be taken to alert you through generating an SNMP trap sending an email ,running a command or creating a alert Manager Incident.

    -Altiris.

    The actions can include sending an email ,generating an SNMP trap,creating an alert Manager or helpdesk incident and running a command on the monitored computer from the command-line.

    -Monitor Solution for Altiris Infrastructure

    When potential problems arise,automated actions can be taken to alert you through generating an SNMP trap,sending an email ,running a command and creating an alert Manager Incident.

    -Veritas Volume Manager 3.0 for Windows 2000 Hotfix 4 Readme file January 8.2003, SNMP trap notifications cannot be viewed(incident 110988) the hotfix corrects this problem.

    -Veritas sanspoint control 3.6

    Actions can also involve sending an SNMP trap logging the incident to a file ,or saving the databasse for report generation.