First thing that you should aways do is think on how you as a human would do
it.
So how would you see the version.  
Now do the same but remember you can't interprete things in the interface of
an application.  This means that the number (version number) should be
somewere in a clear field (typicaly registry or eventlog or SNMP or ...),
once you know that you can see if SA is able to retrieve that or not.
Then the next question is , what exactly do you want to check? Look at the
version number and do what with it?  Alert in what case?
 


Dirk.

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf
Of David Webster
Sent: Thursday, August 05, 2004 9:03 PM
To: [EMAIL PROTECTED]
Subject: [SA-list] Check Version of Symantec anti virus definitions

Hello,

First props to SA, it's creator, and all the SA users who keep the ideas
flowing.  I use SA to monitor many things on WIN2K, WIN2K+3 boxes and
it's great.

I apologize if this question has already been answered.  I searched the
list archives for antivirus, virus, Symantec and did not find anything.

Question:  Is there a way to check that would return what version the
Symantec Antivirus Corporate Edition virus definition files are on a
given server running the AV software?  I did not see a direct check for
it.  I imagine that some combination of event log checking and file
checking on the target machine might do the trick.  Perhaps and add-on
is necessary?  I am fairly experienced with the out-of-the box
capabilities of SA, but have to dabbled in add ones.  Can someone point
me in the right direction?

Thanks in advance.

David

PS running v4.1.1609



-------------------------

[This E-mail scanned for viruses by Declude Virus]

To unsubscribe from a list, send a mail message to [EMAIL PROTECTED]
With the following in the body of the message:
   unsubscribe SAlive






-------------------------

[This E-mail scanned for viruses by Declude Virus]

To unsubscribe from a list, send a mail message to [EMAIL PROTECTED]
With the following in the body of the message:
   unsubscribe SAlive

Reply via email to