Chapter 8
Configuring Antivirus Devices
Export the AntiVirus Agent List
You can export the list of Symantec AntiVirus Clients and Agents as a CSV file (*.csv), which enables
you to use the CSV file to load the agents into MARS. For more information on adding agents from the
file,
agents manually.
To generate the CSV file, follow these steps:
Select = View > Default Console View to ensure the generated CVS file will be based on the Console
Step 1
Default View.
Right-click the name of the server that you want to export, choose Export List, and save it as Text
Step 2
(Comma Delimited) (*.csv) file.
Copy the file to an FTP server that the MARS Appliance can access.
Step 3
You will use this file when you add the AntiVirus agents within the web interface.
Add the Device to MARS
Adding a device to MARS has two distinct steps. First, add the host configuration information . Then,
add its agents, either manually or from the seed file.
For Symantec AntiVirus, the Symantec agent hostname (AV client computer name) appears in the
Tip
"Reported User" column of the event data. Therefore, you can define a query, report or rule related to
this agent based on the "Reported User" value.
To add the host and application configuration information, follow these steps:
Select Admin > Security and Monitor Devices > Add.
Step 1
Select Add SW Security apps on a new host or Add SW security apps on existing host from the
Step 2
Device Type list.
To add a new host, enter the device name and IP addresses.
Step 3
Click Apply.
Step 4
Click the Reporting Applications tab.
Step 5
From the Select Application list, select Symantec AntiVirus 9.x.
Step 6
Click Add, then add the agents. Continue with
Step 7
Add Agent Manually
MARS can automatically discover agents or you can manually add them one at a time or in bulk using a
CSV file (see
agent. The value of defining an agent is that is accelerates the discover process; however, it is not
required.
78-17020-01
Add Agents from a CSV File, page
Add Agents from a CSV File, page
8-8. This approach is much faster than if you had to identify the
Add Agent Manually, page
8-8.) This topic explains how to manually add a single
User Guide for Cisco Security MARS Local Controller
Symantec AntiVirus Configuration
8-7.
8-7