Endpoint Protection

 View Only
Expand all | Collapse all

Enabling "Log files written to USB drives" in SEP client

John Santana

John SantanaFeb 12, 2014 11:17 PM

  • 1.  Enabling "Log files written to USB drives" in SEP client

    Posted Dec 17, 2013 04:50 AM

    Hi People,

    What is the impact when I select that option to be enabled ?

    I wonder where is the log file is kept ? is it in SEPM server, SYSLOG server of our choice or the SEP client ?



  • 2.  RE: Enabling "Log files written to USB drives" in SEP client
    Best Answer

    Posted Dec 17, 2013 04:54 AM


  • 3.  RE: Enabling "Log files written to USB drives" in SEP client

    Broadcom Employee
    Posted Dec 17, 2013 05:18 AM

    the number of events are going to be filled. The log retention settings has to be enabled. If this is not going to be monitored disable the logging.

    and the name of the files are not important right?

     



  • 4.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Dec 17, 2013 05:45 AM

    These events will be in the control log

    How many devices are you doing this for?



  • 5.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Dec 17, 2013 07:41 AM

    The client will have the log, this log will be fwd to SEPM, SEPM will fwd to Syslog



  • 6.  RE: Enabling "Log files written to USB drives" in SEP client

    Broadcom Employee
    Posted Dec 17, 2013 10:32 AM

    Hi John,

    Thank you for posting in Symantec community.

    Under Application & device control policy you can select the option for "Log files written to USB drives."

    The logs can viewed under

    Logs can be viewed in SEP client console under View Logs menu > Client Management > Control Log...
    Logs can be viewed in SEP Manager under Monitors menu > Logs tab - Log Type: Application and Device Control, Log Content: Application Control - Select View Log

    Reference: http://www.symantec.com/connect/forums/how-see-written-activity-usb-drive



  • 7.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Dec 17, 2013 09:13 PM

    Brian,

    in the office, we've got 300 workstations.

    Does this going to effect the SEPM C:\ drive or it will be pushed to the External Syslog server that I have already configured in the External Logging option ?



  • 8.  RE: Enabling "Log files written to USB drives" in SEP client
    Best Answer

    Posted Dec 17, 2013 09:17 PM

    In addition to going to syslog, it will stay on the SEPM based on the number of days you configured the SEPM to keep logs



  • 9.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Feb 12, 2014 11:17 PM

    Cool, thanks People !



  • 10.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Feb 14, 2014 07:53 AM

    Not trying to hijack this thread, but a question on this:

    Where exactly may I set the days that SEPM keeps the logs of Application & Device Control?
    In practice, I want to know the files users have copied and devices that have been disabled.

    In the SQL-Settings I have various possibilities as I see and have set up ("Management Server Log Settings", "Client Log Settings", "Risk Log Settings"). But none of these settings seems to correlate with the effective logged data I get presented after checking the logs.

    Am I missing something there?



  • 11.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Feb 14, 2014 07:48 PM

    it's alright, sharing the knowledge here is good :-)



  • 12.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Feb 14, 2014 08:10 PM

    In the SEPM, go to Admin >> Servers and select your DB and select Edit Database Properties

    On the Log Settings tab is where you can configure this. The Control Log Limit is the one.



  • 13.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Feb 15, 2014 07:29 AM

    Thanks for the replies!
    I will check this on monday :)

    Have a nice weekend guys



  • 14.  RE: Enabling "Log files written to USB drives" in SEP client

    Posted Feb 17, 2014 04:42 AM

    Alright then, reply to this one.

    In my current setup, I got the following settings:pic74.jpg
    To my understanding, the "Control Log Limit" should then define the days / count of entries in the database.

    Still somewhat confusing to me is the fact that "60 days" is configured, but I seem to be able to access data back from 6 months (Application & Device Logs). So is this really defined by "Control Log Limit"?
    Nevertheless, I need at least 365 days of history.