Symantec EPM

When you configure your Symantec EPM to send log data to USM Appliance, you can use the Symantec EPM plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin.

Plugin Information
Device Details
Vendor Symantec
Device Type Endpoint Management
Connection Type Syslog
Data Source Name symantec-epm
Data Source ID 1619

Integrating Symantec EPM

Before you configure the Symantec EPM integration, you must have the IP Address of the USM Appliance Sensor.

To configure Symantec EPM to send log data to the USM Appliance Sensor

  1. In the console, click Admin.
  2. Click Servers.
  3. Click the local site or remote site that you want to export log data from.
  4. Click Configure External Logging.
  5. On the General tab, in the Update Frequency list box, select how often to send the log data to the file.
  6. In the Master Logging Server list box, select the management server to send the logs to.

    Note: If you use SQL Server and connect multiple management servers to the database, specify only one server as the Master Logging Server.

  7. Check Enable Transmission of Logs to a Syslog Server.
  8. Provide the following information:

    1. Syslog Server: Enter the IP address or domain name of the USM Appliance Sensor that you want to receive the log data.
    2. Destination Port: Select UDP as the protocol to use, and type 514 as the destination port that the USM Appliance Sensor uses to listen for syslog messages.
    3. Log Facility: Enter the number of the log facility that you want to the syslog configuration file to use, or use the default.

      Valid values range from 0 to 23.

  9. On the Log Filter tab, select the logs you want to export. The Symantec EPM plugin can parse all these logs.
  10. Click OK.

Plugin Enablement

For plugin enablement information, see Enable Plugins.

Additional Resources and Troubleshooting

http://www.symantec.com/connect/forums/external-logging-syslog-server

For troubleshooting, refer to the vendor documentation:

https://www.symantec.com/content/dam/symantec/docs/education/endpoint-protection-12-1-maintain-and-troubleshoot-course-desc-generic-en.pdf