Houston Security User Group

 View Only
  • 1.  How often are the Logs sent to the SEPM(SEP 11)

    Posted Mar 06, 2013 10:28 AM

    I want to make sure, but how often are the Log sent to the SEPM. I see that a setting is at 7200 seconds, but is that correct.

     

    If I am wrong where is the setting?

     

    Thanks,

     



  • 2.  RE: How often are the Logs sent to the SEPM(SEP 11)

    Posted Mar 06, 2013 10:31 AM
    For clients correct? This is found on Clients page on the Policies tab - Clients log settings. Is this where you set it? This is only client settings, not for sepm However logs will be sent to sepm based on heartbeat setting. This is when this process is done.


  • 3.  RE: How often are the Logs sent to the SEPM(SEP 11)

    Posted Mar 06, 2013 11:15 AM

    Thanks, I thought it was based on the Heartbeat.



  • 4.  RE: How often are the Logs sent to the SEPM(SEP 11)

    Posted Mar 06, 2013 11:17 AM

    Logs will be sent based on Heartbeat setting..



  • 5.  RE: How often are the Logs sent to the SEPM(SEP 11)

    Posted Mar 06, 2013 11:18 AM

    Soem more reference to that:

    Managing log data in the Symantec Endpoint Protection Manager (SEPM)
     http://www.symantec.com/docs/TECH153987

    Accortind to the documentation - Heartbeat interval = Frequency in which client upload data to SEPM



  • 6.  RE: How often are the Logs sent to the SEPM(SEP 11)

    Posted Mar 06, 2013 11:20 AM

    You can also check this out in regards to the setting you set. It gives a full explanation:

    About configuring event aggregation in the SEPM

    Article:HOWTO27472  |  Created: 2010-01-08  |  Updated: 2012-09-25  |  Article URL http://www.symantec.com/docs/HOWTO27472

     

    On the Clients page, Policies page, Client Log Settings

    Use this location to configure the aggregation of Network Threat Protection events. Events are held on the clients for the damper period before they are aggregated into a single event and then uploaded to the console. The damper period helps to reduce events to a manageable number. The default damper period setting is Auto (Automatic). The damper idle period determines the amount of time that must pass between log entries before the next occurrence is considered a new entry. The default damper idle is 10 seconds.



  • 7.  RE: How often are the Logs sent to the SEPM(SEP 11)

    Posted Mar 06, 2013 04:53 PM

    Good one brian