Video Screencast Help
Search Video Help Close Back
to help

In SEPM, How to increase syslog information logged?

Created: 25 Dec 2012 | Updated: 25 Dec 2012 | 3 comments
marionb's picture
0 0 Votes
Login to vote

Hi all,

 

I am using the External Logging feature to export most of my SEPM logs to logs file.

Unfortunately, some of the most important information doesn't appear in the log files, although it is accessible via the GUI.

 

For example:

1. the unique ID is missing in every log

2. I audit "writing to USB devices", and the serial number and file size are not logged via syslog (although they appear in the sepm db).

 

My question is - can I change that? can I set a more verbose syslog logging?

 

Thanks,

Marion.

Comments 3 CommentsJump to latest comment

marionb's picture

Thanks Ashish, but unfortunately the thread treats a bit different subject.

 

Is there any way to increase the auditing level to syslog (server or dump file) ? 

0
Login to vote
Ashish-Sharma's picture

hi,

Try to increase severity levels...

What sepm version are you using ?

 

Exporting data to a Syslog server

Article:HOWTO27571  |  Created: 2010-01-09  |  Updated: 2010-01-20  |  Article URL http://www.symantec.com/docs/HOWTO27571
 

Symantec Endpoint Protection Manager logs all messages to syslog server with Informational severity

Article:TECH98148  |  Created: 2009-01-16  |  Updated: 2010-08-17  |  Article URL http://www.symantec.com/docs/TECH98148
 

 

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

0
Login to vote