web analytics

SYMANTEC ENDPOINT PROTECTION MANAGER

Log Forwarding > Applications > Symantec Endpoint Protection Manager

Instructions for forwarding Symantec Endpoint Protection Manager logs to your Log Management device

PREREQUISITES

Symantec Endpoint Protection Manager (SEPM) v12

  • The IP Address for the Symantec Endpoint Protection Manager
  • Credentials to access Symantec Endpoint Protection

Clone Systems Log Management Device

  • The IP Address for the Clone Systems Log Management device

INSTRUCTIONS

1

Log onto the server that Symantec Endpoint Protection Manager (SEPM) is installed on. Launch SEPM and enter your Username and Password. And then click the Log On button.

2

Click Admin from the toolbar on the left.

3

Click Servers

4

Click the local site or remote site that you want to export log data from

5

Click Configure External Logging

6

On the General tab, in the Update Frequency list box, select how often to send the log data to the file

7

In the Master Logging Server list box, select the management server to send the logs to.

If you use SQL Server and connect multiple management servers to the database, specify only one server as the Master Logging Server

8

Check Enable Transmission of Logs to a Syslog Server

9

Provide the following information:

Syslog Server

Type the IP Address of Clone Systems Log collector

Destination Port

Select the TCP protocol to use, and type the destination port that the Syslog server uses to listen for Syslog messages.

Log Facility

Leave this setting alone

10

On the Log Filter tab, check which logs to export

11

Click OK and confirm that the log messages are being sent to the Clone Systems Log Management device.