Security Compliance
Set up OfficeScan message logging with SEM
This article provides information on how to set up OfficeScan to send syslogs to SEM.
First published date
Last published date
Overview
Product section
Resolution
Note: The Trend Office Scan connector is available under the agent, but under the 'Anti-Virus' connector category.
In the HTML5 SEM Events Console (SEM versions 6.6 and later):
- Click the Nodes tab, select the agent, and then click Manage node connectors.
- In the search box, enter trend office.
In the SEM Flash Console:
- On the SEM console menu bar, navigate to Manage > Nodes, click on the Gear icon of the machine agent where it installed, and then click Connectors.
- In the search box, enter trend office.
A. Confirm the syslog is transmitting:
Confirm that OfficeScan is configured correctly to send log data to the Windows application log by opening the log in the Windows Event Viewer. If Trend events do not appear in the Windows log, SEM connectors cannot get them.B. Confirm the integration of the Windows server and SEM:
- Install SEM agent on the Windows server that is hosting the Trend Micro anti-virus. Be sure to install the agent with run as-admin for the install, which gives the agent permission to send events to SEM.
- Once the Windows server is added/integrated with SEM, the server name appears in the list of Nodes in your SEM console and SEM Events Console.
C. Set up the Connector:
In the HTML5 SEM Events Console:- Select the node you configured above, and then click Manage node connectors.
- In the search box, enter trend office.
- Select the Trend Office Scan connector, and then click Add Connector.
- Ensure the Log File location is set to application, and then click Add.
- Under Configured connectors, select the connector, and then click Start.
- Select the node with this server name.
- Click on the gear icon.
- Click on connectors.
- For this node, the OfficeScan connector appears on the list.
- Once you have located the OfficeScan connector, configure the details accordingly with the same location where the syslogs are being sent to will be the Application log).