I found TECH article # 186925 (http://www.symantec.com/docs/TECH186925) that the Symantec Endpoint Manager 12.1 writes to the Application Log. However, it has been my experience that you can find Events in the Symantec Endpoint Protection Log as well.
If you are trying to monitor Events for Symantec Endpoint Manager, is it good practice to look at the Application Log or the Symantex Endpoint Protection Log or maybe both?
You want to find these in the System log on the SEP client.
SEP will also write to it's own Windows event log called Symantec Endpoint Protection Client.
However, the logs on the SEP client will contain more info for sure.
For SEPM look under application log
Thank you. I appreciate the input.