Security Compliance
Integrate Symantec Endpoint Protection 11 or later with SolarWinds SEM
This article provides procedures for configuring Symantec Endpoint Protection 11 or later to log to your SEM appliance and configuring the Symantec Endpoint Protection 11 connector on your SEM manager.
First published date
Last published date
Overview
Product section
Resolution
To configure Symantec Endpoint Protection to log to the SEM appliance:
- Open Symantec Endpoint Protection (SEP).
- Click Admin, and then select Servers > Local Site > Configure External Logging.
- In the External Logging for Local Site window, select Enable Transmission of Logs to a Syslog Server.
- In the Syslog Server field, enter the IP address of your SEM appliance.
- In the Log Facility field, enter
22.Note: The Log Facility value in SEP is equal to the local facility on your SEM appliance plus 16, so the default local facility of local6 in the SEP connector for the SEM manager equates to Log Facility 22 in SEP and change default syslog port changed from 1468 to 514
- In the Log Line Separator field, select CR.
- Click the Log Filter tab.
- Select the logs you want to send to your SEM appliance.
- Click OK.
To configure the Symantec Endpoint Protection 11 connector on the SEM manager:
A connector for the Windows Application log still exists because earlier versions of SEP do not generate syslog data.
SEM HTML5 console (versions 6.6 and newer)
- In the SEM Events Console, navigate to Nodes > Manager Connectors.
- In the search box, enter symantec.
- Select the Symantec Endpoint Protection 11 connector, and then click Add Connector.
- Enter a new name, or maintain the default.
- If you entered a Log Facility value other than 22 in SEP, verify the Log File value in your SEM connector matches the Log Facility defined in Step 5 above.
- Click Add.
- Under Configured connectors, select the connector, and then click Start.
SEM Flash console
- On the SEM console menu bar, navigate to Manage > appliances, and then log in to the SEM manager as an administrator.
- Next to your SEM manager, click the gear icon, and then select Connectors.
- In the Connector Configuration window, enter
Symantec Endpoint Protection 11in the search box at the top of the Refine Results pane. - Next to the Symantec Endpoint Protection 11 connector, click the gear icon, and then select New.
- Enter a custom Alias or accept the default.
- If you entered a Log Facility value other than 22 in SEP, verify the Log File value in your SEM connector matches the Log Facility defined in Step 5 above.
- If you are finished configuring the connector, click Save.
- Next to the new connector (denoted by an icon in the Status column), click the gear icon, and then click Start.
- To exit the Connector Configuration window, click Close.
After the connector starts, test your integration using a trusted antivirus test site, such as www.eicar.org (© YYYY2019 eicar, available at https://www.eicar.org/, obtained on December 2, 2019) .
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.