Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

eTrust message record and action

Status
Not open for further replies.

dlom

Technical User
Aug 26, 2003
4
US
I am trying to create a message record and action for eTrust Antivirus messages that contain "File Status: Cure failed, file restored." Here's an example of a message from the Console Log:

[time 12/17/2004 1:58:02 AM: ID 14: machine hostname.domain.com: response 12/17/2004 2:03:30 AM] The HTML.Phishbank.BD was detected in Volume:\Folder1\Folder2\Folder3\File.AVB. Machine: hostname, User: administrator. File Status: Cure failed, file restored.

The problem I'm running into is that the "File Status: Cure failed, file restored." part of the message is not always in the same position (as in &(24:29)). Is there a way to search for this string in the message record, or filter for it somehow in the message action using TEST, regardless of the position of the string?

Thanks.
 
Maybe you can create a MRA that contains the msgid=* and in the scan tab, add the string you're looking for.

Luck

Américo Alonso
Certified Unicenter Engineer
Bull Uruguay S.A.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top