Where does SEPM Client keeps its logs when it is disconnected to the server?

Nel Ramos's picture

Hi Team,

If a computer was disconnected from the SEPM server then it could not send its risk logs...
Until it is connected, that is the only time that the SEPM server could get its logs and then report if a risk has been found via console.

Where does SEPM client keeps its monitoring logs.. example virus infections?

Thanks.

Paul Mapacpac's picture

Re

the most detailed log is found on the client itself, open the SEP gui, then click the Logs. You will all the logs there, Risk, System logs etc..

Nel Ramos's picture

Hi Paul.. what I mean is.. is

Hi Paul..
what I mean is.. is there a way to know where SEPM keeps the virus logs? Files?
thanks...

Nel Ramos

Paul Mapacpac's picture

Re

If I remember correctly, it should be on %System Drive%\Documents and Settings\All User\Symantec folder, go on to the folders inside, but I am not sure if you can view these logs via notepad.

Nel Ramos's picture

and if these files were to be

and if these files were to be erased by a client, it will not anymore report to the server once connected?
Just checking some vulnerabilities here...
thanks...
and by the way.. the file? hope you could still remember it SIr..
thanks..

Nel Ramos

pete_4u2002's picture

hi, yes: if the client logs

hi,
yes: if the client logs are deleted while offline , the next moment SEP client connects SEPM, the existing logs only be processed.

and by the way.. the file? I believe this is the file Paul was referring to..C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Logs

cheers

Pete

Paul Mapacpac's picture

Re

Hi Nel you check the permissions set on this folder or file, I believe its SYSTEM, but please double check.

Bijay.Swain's picture

C:\Documents and Settings\All

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Logs

this is the actual locationo of clients log files.It is kept in datewise format. you can also delete the logs from here

Nel Ramos's picture

thanks All for the

thanks All for the feedback...
Could a client alter the files in the logs so to prevent SEPM client to report to SEPM server once connected again to the network?
They might delete the contents thus making SEPM client report nothing...
thanks

Nel Ramos

Paul Mapacpac's picture

Re

If I remember correctly, if you allow the user to have access on the Logs button, then they can delete the logs.

Nel Ramos's picture

thanks.. Good to know

thanks..
Good to know that..
What possibly are the files extesions that carry the logs?
thanks..

Nel Ramos

Paul Mapacpac's picture

Re

I believe it's .log

Sandeep Cheema's picture

Analysis

And this is how you would interpret the logs if you would have to:

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2002111911231448

Nel Ramos's picture

thanks for the help...

thanks for the help...

Nel Ramos