Skip to content

Commit de0a869

Browse files
committed
minor fixes on naming conventions
1 parent f61cd6e commit de0a869

File tree

1 file changed

+11
-11
lines changed

1 file changed

+11
-11
lines changed

docs/integrations/saas-cloud/symantec-endpoint-security-service.md

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
id: symantec-endpoint-security-service
3-
title: Symantec Endpoint Security Service
4-
sidebar_label: Symantec Endpoint Security Service
3+
title: Symantec Endpoint Security
4+
sidebar_label: Symantec Endpoint Security
55
description: The Sumo Logic app for Symantec Web Security provides real-time insights into the log data by leveraging the Symantec Endpoint Security Service.
66
---
77

@@ -20,7 +20,7 @@ This app includes [built-in monitors](#symantec-endpoint-security-monitors). For
2020

2121
This app uses [Symantec Endpoint Security Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-endpoint-security-source/) to collect Incidents and Event Logs from Symantec Endpoint Security.
2222

23-
## Sample log message
23+
### Sample log message
2424

2525
<details>
2626
<summary>Incident Log</summary>
@@ -142,7 +142,7 @@ This app uses [Symantec Endpoint Security Source](/docs/send-data/hosted-collect
142142
```
143143
</details>
144144

145-
## Sample queries
145+
### Sample queries
146146

147147
```sql title="Incidents by Severity"
148148
_sourceCategory="Labs/SES" !device_uid
@@ -211,27 +211,27 @@ _sourceCategory="Labs/SES" device_uid
211211

212212
## Set up collection
213213

214-
To set up the [Cloud-to-Cloud Integration for Symantec Endpoint Security Service Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-endpoint-security-source/), follow the instructions provided. These instructions will guide you through the process of creating a source using the Symantec Endpoint Security Service Source category, which you will need to use when installing the app. By following these steps, you can ensure that your Symantec Endpoint Security Service app is properly integrated and configured to collect and analyze your Symantec Endpoint Security Service data.
214+
To set up the [Cloud-to-Cloud Integration for Symantec Endpoint Security Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-endpoint-security-source/), follow the instructions provided. These instructions will guide you through the process of creating a source using the Symantec Endpoint Security Source category, which you will need to use when installing the app. By following these steps, you can ensure that your Symantec Endpoint Security app is properly integrated and configured to collect and analyze your Symantec Endpoint Security data.
215215

216-
## Installing the Symantec Endpoint Security Service app
216+
## Installing the Symantec Endpoint Security app
217217

218218
import AppInstall2 from '../../reuse/apps/app-install-v2.md';
219219

220220
<AppInstall2/>
221221

222-
## Viewing the Symantec Endpoint Security Service dashboards
222+
## Viewing the Symantec Endpoint Security dashboards
223223

224224
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
225225

226226
<ViewDashboards/>
227227

228228
### Incidents Overview
229229

230-
The **Symantec Endpoint Security Service - Incidents Overview** dashboard provides a detailed view of endpoint incidents through various widgets. These widgets display data such as the total number of incidents, total count of open incidents, high severity incidents, high priority incidents, cynic detection, newly identified incidents, unknown incidents, incidents distribution by event type, severity, category, conclusion, detection type, state, priority, and suspected breach. Additionally, it includes incident resolution rates, incidents over time, average resolution time of incidents, sandbox detections over time, summaries of all incidents, unresolved incidents, and remediation specifics. This enables administrators to monitor and manage endpoint security effectively in real time, promptly identifying and addressing potential incidents.<br/><img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Symantec+Endpoint+Security+Service/Symantec-Endpoint-Security-Incidents-Overview.png')} alt="Symantec-Endpoint-Security-Service-Incidents-Overview" width="800"/>
230+
The **Symantec Endpoint Security - Incidents Overview** dashboard provides a detailed view of endpoint incidents through various widgets. These widgets display data such as the total number of incidents, total count of open incidents, high severity incidents, high priority incidents, cynic detection, newly identified incidents, unknown incidents, incidents distribution by event type, severity, category, conclusion, detection type, state, priority, and suspected breach. Additionally, it includes incident resolution rates, incidents over time, average resolution time of incidents, sandbox detections over time, summaries of all incidents, unresolved incidents, and remediation specifics. This enables administrators to monitor and manage endpoint security effectively in real time, promptly identifying and addressing potential incidents.<br/><img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Symantec+Endpoint+Security+Service/Symantec-Endpoint-Security-Incidents-Overview.png')} alt="Symantec-Endpoint-Security-Incidents-Overview" width="800"/>
231231

232232
### Events Overview
233233

234-
The **Symantec Endpoint Security Service - Events Overview** The "Symantec Endpoint Security - Events Overview" dashboard provides a comprehensive view of endpoint security status through various widgets. These widgets display key data such as the total number of events, high severity events, suspicious files, event distribution based on severity, category, event type, EDR event type, affected endpoints, top users linked to events, top malicious files, top SHA256 of files, top affected IPs, events over time, sandbox file detection events over time, and summaries of malicious files, events, hosts, threats, and incidents with the device. The dashboard also includes information on geographic locations of affected endpoints, and helps administrators monitor, manage, and respond to security threats in real time. This enables businesses to secure endpoints and defend against a wide range of threats.<br/><img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Symantec+Endpoint+Security+Service/Symantec-Endpoint-Security-Events-Overview.png')} alt="Symantec-Endpoint-Security-Service-Events-Overview" width="800"/>
234+
The **Symantec Endpoint Security - Events Overview** The "Symantec Endpoint Security - Events Overview" dashboard provides a comprehensive view of endpoint security status through various widgets. These widgets display key data such as the total number of events, high severity events, suspicious files, event distribution based on severity, category, event type, EDR event type, affected endpoints, top users linked to events, top malicious files, top SHA256 of files, top affected IPs, events over time, sandbox file detection events over time, and summaries of malicious files, events, hosts, threats, and incidents with the device. The dashboard also includes information on geographic locations of affected endpoints, and helps administrators monitor, manage, and respond to security threats in real time. This enables businesses to secure endpoints and defend against a wide range of threats.<br/><img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Symantec+Endpoint+Security+Service/Symantec-Endpoint-Security-Events-Overview.png')} alt="Symantec-Endpoint-Security-Events-Overview" width="800"/>
235235

236236
## Create monitors for Symantec Endpoint Security app
237237

@@ -253,13 +253,13 @@ import CreateMonitors from '../../reuse/apps/create-monitors.md';
253253
| `Spike in Impacted Devices Count` | This alert is triggered when a spike is detected in the number of impacted devices. It helps you to monitor and stop potentially harmful devices, enhancing your ability to identify suspicious activity. | Critical | Count > 0 |
254254
| `Unresolved Incident Aging Beyond 7 days` | This alert is triggered when an incident is created and remains unresolved for 7 days. It helps you to monitor pending incidents for an extended period, enhancing your ability to identify suspicious activity. | Critical | Count > 0 |
255255

256-
## Upgrade/Downgrade the Symantec Endpoint Security Service app (Optional)
256+
## Upgrade/Downgrade the Symantec Endpoint Security app (Optional)
257257

258258
import AppUpdate from '../../reuse/apps/app-update.md';
259259

260260
<AppUpdate/>
261261

262-
## Uninstalling the Symantec Endpoint Security Service app (Optional)
262+
## Uninstalling the Symantec Endpoint Security app (Optional)
263263

264264
import AppUninstall from '../../reuse/apps/app-uninstall.md';
265265

0 commit comments

Comments
 (0)