Endpoint Protection

 View Only
Expand all | Collapse all

Clarification regarding the SEPM logged event

  • 1.  Clarification regarding the SEPM logged event

    Posted Dec 17, 2013 04:55 AM

    As per my understanding, All events checked will be sent from the client to the management server, but 

    -      Which events are checked?

    -      Does this mean that all agents systems forward the AV logs to the Symantec server?



  • 2.  RE: Clarification regarding the SEPM logged event

    Posted Dec 17, 2013 04:59 AM

    Below is a list of events that are logged on the local client and forwarded on to the Symantec Endpoint Protection Manager. Many, but not all, of these events appear in the Windows Application Log

    http://www.symantec.com/business/support/index?page=content&id=TECH105571



  • 3.  RE: Clarification regarding the SEPM logged event
    Best Answer

    Broadcom Employee
    Posted Dec 17, 2013 05:23 AM

    yes AV log information like system scan, pattern date, infection found and action are sent to the SEPM.

    when you check the monitor --> logs  you will find the relevant log information from clients to server.



  • 4.  RE: Clarification regarding the SEPM logged event

    Posted Dec 17, 2013 05:53 AM

    You can set the options for what you want sent in the policy

    All agents that are connected to the SEPM will send their logs



  • 5.  RE: Clarification regarding the SEPM logged event
    Best Answer

    Broadcom Employee
    Posted Dec 17, 2013 06:00 AM

    Hi,

    Thank you for posting in Symantec community.

    Events that are logged on the local client and forwarded on to the Symantec Endpoint Protection Manager. Many, but not all, of these events appear in the Windows Application Log.

    Following aritcle should answer your query.

    Smantec Endpoint Protection 12.1.x event log entries

    http://www.symantec.com/docs/TECH186925



  • 6.  RE: Clarification regarding the SEPM logged event

    Posted Dec 17, 2013 08:26 PM

    Thanks for all who responds to my thread.

    "Many, but not all, of these events appear in the Windows Application Log"

    Does that means the list of events in the http://www.symantec.com/business/support/index?page=content&id=TECH186925 are all logged in the SEPM server and some other events (not listed in there) are also listed in the WIndows Event Viewer \ Application log ?



  • 7.  RE: Clarification regarding the SEPM logged event
    Best Answer

    Posted Dec 17, 2013 09:00 PM

    with SEP 12.1.4 you will find Symantec endpoint proection in the eventvwr.



  • 8.  RE: Clarification regarding the SEPM logged event

    Posted Dec 17, 2013 09:14 PM

    Rafeeq,

    So in this case all of those Event in the article will be logged in the Windows Event viewer not forwarded to the SEPM server or to the External Logging server ?



  • 9.  RE: Clarification regarding the SEPM logged event
    Best Answer

    Posted Dec 17, 2013 09:16 PM

    They will be sent to the SEPM and forwarded to syslog assuming you configured them to do so



  • 10.  RE: Clarification regarding the SEPM logged event
    Best Answer

    Broadcom Employee
    Posted Dec 17, 2013 09:35 PM

    SEPM will get the events from SEP client, then you need to configure the SEPM to forward the logging to external server.



  • 11.  RE: Clarification regarding the SEPM logged event

    Broadcom Employee
    Posted Dec 18, 2013 04:27 AM

    You are right.



  • 12.  RE: Clarification regarding the SEPM logged event

    Posted Feb 24, 2014 10:14 AM

    Do you need more assistance with your problem or were you able to get it resolved?

    If you could post an update for followers of this thread that would be most helpful.

    Otherwise, if resolved, you can close the thread out by clicking the "Mark as solution" link at the bottom left on the most helpful post. If multiple posts helped to solve your problem, please click the "Request split solution" link at the bottom left, select the most helpful posts and click the "Submit" button. This will benefit admins looking for a resolution to the same problem.

    Thanks and take care,
    Brian



  • 13.  RE: Clarification regarding the SEPM logged event

    Posted Feb 27, 2014 06:04 PM

    Many thanks all for the clarification !