diff --git a/Content/Content Packs/Symantec Endpoint Content Pack.htm b/Content/Content Packs/Symantec Endpoint Content Pack.htm index 30dd74a..2c9a511 100644 --- a/Content/Content Packs/Symantec Endpoint Content Pack.htm +++ b/Content/Content Packs/Symantec Endpoint Content Pack.htm @@ -1,217 +1,245 @@  - - Symantec Endpoint Content Pack + + + Symantec Endpoint Content Pack -

-

-
Hint: This content pack was first released in Illuminate v3.2.0.
-
-

-

Symantec Endpoint Protection is a security software suite that consists of anti-malware, intrusion prevention, and firewall features for server and desktop computers. This technology pack will process Symantec logs, providing normalization and enrichment of common events of interest.

-

Supported Version(s) -

+

Symantec Endpoint Protection is a security software suite that consists of anti-malware, intrusion prevention, and firewall features for server and desktop computers. This technology pack will process Symantec logs, providing normalization and enrichment of common events of interest.

+

Supported Version(s)

-

Stream Configuration -

-

This technology pack includes one stream:

+

Requirements

+

Stream Configuration

+

This technology pack includes 1 stream:

+

-
Hint: If this stream does not exist prior to the activation of this pack, then it will be created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.
+
Hint: If this stream does not exist prior to the activation of this pack then it will be created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream. +

-

Index Set Configuration -
-

-

This technology pack includes one index set definition:

+

Index Set Configuration

+

This technology pack includes 1 index set definition:

-
Hint: If this index set is already defined, then nothing will be changed. If this index set does not exist, then it will be created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.
+
Hint: If this index set is already defined, then nothing will be changed. If this index set does not exist, then it will be created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation. +

-

Event Types Supported -

-