Logmanager documentation
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Symantec Endpoint Protection Manager

This document describes how to configure Symantec EPM device to send the log data to a Logmanager server.

After configuring EPM device you need to correctly configure Classifiers in Logmanager to have data correctly parsed in Logmanager.

For detailed information about Symantec EPM see https://support.symantec.com/en_US/article.HOWTO81168.html#v8440135

Configuring remote logging to syslog

To export log data to a Syslog server

  1. In the console, click Admin.

  2. Click Servers.

  3. Click the local site or remote site that you want to export log data from.

  4. Click Configure External Logging.

    Symantec Endpoint Protection Manager Syslog

    Symantec Endpoint Protection Manager Syslog

  5. On the General tab, in the Update Frequency list box, select how often to send the log data to the file.

  6. In the Master Logging Server list box, select the management server to send the logs to.

  7. Check Enable Transmission of Logs to a Syslog Server.

  8. Provide the following information:

    • Syslog Server

      Type the IP address or domain name of the Logmanager server that you want to send audit data to.

    • Destination Port

      Select the protocol to use, and type the destination port that the Logmanager server uses to listen for Syslog messages.

    • Log Facility

      Type the number of the log facility that you want to use for the Syslog messages, or use the default. Valid values range from 0 to 23.

    External Logging for Local Site - General

    External Logging for Local Site - General

  9. On the Log Filter tab, check which logs to export.

  10. Click OK.

    External Logging for Local Site - Log Filter

    External Logging for Local Site - Log Filter