All Apps and Add-ons

Kaspersky GNRL_EV_VIRUS_FOUND "action" value

mailmetoramu
Explorer

In my Splunk environment Kaspersky logs, I was able to extract a few more fields based. However, looking at some of the logs, where viruses are found, I'm not sure what the action should be since there is nothing in the logs indicating what it should be.

The logs that contain "GNRL_EV_VIRUS_FOUND" - the action is currently mapping to unknown with the automatic lookup that is in place. This is happening because we are not able to determine what action should be, i believe this should be mapped to "allowed", but not entirely sure.

I was not able to find any Kaspersky documentation that would help determine this. Are you able to provide any Kaspersky documentation that could help? Also if any documentation regarding the logs for field mapping.

Looking for your reply.

Thanks,

Ramu.R

Tags (1)
0 Karma
1 Solution

nickhills
Ultra Champion

This post: http://certsrv.ru/klakaut.en/a00031.html

Suggests that 'GNRL_EV_VIRUS_FOUND' means that Kaspersky has found a virus, but it does not indicate the action taken.
I would assume in most cases, this first message would be followed with one of:

"GNRL_EV_OBJECT_CURED" – Object was cured.
"GNRL_EV_OBJECT_DELETED" – Object was deleted.
"GNRL_EV_OBJECT_QUARANTINED" – Object was put into quarantine.
"GNRL_EV_OBJECT_NOTCURED" – Object wasn't cured.

Which indicates the action taken on the affected object.

This makes sense to me, Kaspersky "finds" and virus, then it tries to "deal" with it, and then tells you which of those 4 actions it was "able" to do.

If my comment helps, please give it a thumbs up!

View solution in original post

nickhills
Ultra Champion

This post: http://certsrv.ru/klakaut.en/a00031.html

Suggests that 'GNRL_EV_VIRUS_FOUND' means that Kaspersky has found a virus, but it does not indicate the action taken.
I would assume in most cases, this first message would be followed with one of:

"GNRL_EV_OBJECT_CURED" – Object was cured.
"GNRL_EV_OBJECT_DELETED" – Object was deleted.
"GNRL_EV_OBJECT_QUARANTINED" – Object was put into quarantine.
"GNRL_EV_OBJECT_NOTCURED" – Object wasn't cured.

Which indicates the action taken on the affected object.

This makes sense to me, Kaspersky "finds" and virus, then it tries to "deal" with it, and then tells you which of those 4 actions it was "able" to do.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...