Endpoint Detection and Response tuning for server Operating Systems
book
Article ID: 408479
calendar_today
Updated On:
Products
Endpoint SecurityEndpoint Security for ServersEndpoint Security CompleteEndpoint Detection and ResponseEndpoint Detection and Response CloudEndpoint Protection with Endpoint Detection and Response
Issue/Introduction
Through testing and deployment of Symantec Endpoint Detection and Response (EDR) to servers in an environment, tuning may be required to achieve optimal operating performance for the servers.
Environment
Symantec Endpoint Detection and Response (SEDR)
Resolution
Below is a high-level procedure for tuning EDR events for server operating systems:
In the cloud console, create a designated test Device Group and move the target servers into it.
Note: Creating this as a sub-group allows it to inherit policies from the parent group.
Allow the existing EDR policy to run on the test servers for a minimum of one week to collect a baseline of event data.
Filter Event Data by navigating to the Investigate page within the console. Apply filters to restrict the view exclusively to devices within your designated test group.
Identify the event categories generating the majority of the EDR event stream. Do this using one of the following methods:
In-Console: Use the Group By function to isolate specific event attributes (e.g., Event Type, Actor, Actor Command Line) for use in Endpoint Activity Recorder (EAR) exclusion rules.
Offline Analysis: Click Download Grid > All Columns > OK to export the search results to a CSV file for review in a spreadsheet application.
Duplicate the currently applied EDR policy. Add the new EAR exclusion rules identified during your analysis to the duplicated policy, and assign it to your test group to validate the tuning.