Endpoint Protection

 View Only
  • 1.  SEP Manager Syslogs interpretation

    Posted Feb 15, 2017 08:45 AM

    Hi,

    This is SEP Manager sample syslog event

    <54>Jan 10 01:12:11 SEPM host: xxx001,Local: 123.123.12.30,Local: 80,Local: 0014DBGF2150,Remote: 9.9.9.34,Remote: ,Remote: 50229,Remote: 00155D731D00, ……

    What does the "Local" and "Remote" mean? Is it the same as source IP and destination IP respectively?

    thanks

     



  • 2.  RE: SEP Manager Syslogs interpretation

    Posted Feb 15, 2017 10:04 AM

    Local is your machine for example and remote is another machine trying to talk to yours