How often are the Logs sent to the SEPM(SEP 11)
Created: 06 Mar 2013 | 6 comments
I want to make sure, but how often are the Log sent to the SEPM. I see that a setting is at 7200 seconds, but is that correct.
If I am wrong where is the setting?
Thanks,
Operating Systems:
Discussion Filed Under:
Comments 6 Comments • Jump to latest comment
For clients correct? This is found on Clients page on the Policies tab - Clients log settings. Is this where you set it? This is only client settings, not for sepm
However logs will be sent to sepm based on heartbeat setting. This is when this process is done.
SEP Knowledge Base
Endpoint SWAT
Thanks, I thought it was based on the Heartbeat.
Logs will be sent based on Heartbeat setting..
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Soem more reference to that:
Managing log data in the Symantec Endpoint Protection Manager (SEPM)
http://www.symantec.com/docs/TECH153987
Accortind to the documentation - Heartbeat interval = Frequency in which client upload data to SEPM
You can also check this out in regards to the setting you set. It gives a full explanation:
About configuring event aggregation in the SEPM
On the Clients page, Policies page, Client Log Settings
Use this location to configure the aggregation of Network Threat Protection events. Events are held on the clients for the damper period before they are aggregated into a single event and then uploaded to the console. The damper period helps to reduce events to a manageable number. The default damper period setting is Auto (Automatic). The damper idle period determines the amount of time that must pass between log entries before the next occurrence is considered a new entry. The default damper idle is 10 seconds.
SEP Knowledge Base
Endpoint SWAT
Good one brian
Mohan Babu
moglie20@gmail.com
+91 9884382160
Your satisfaction is very important to us.If you find above information helpful or it has resolved your issue...please mark it accordingly :)
Would you like to reply?
Login or Register to post your comment.