
Site: SEPSite,Server: SEPServer,Domain: _domainOrigin,Admin: _originUser,Administrator log on succeeded Agent Activity Log See vendor documentation: External Logging settings and log event severity levels for Endpoint Protection Manager Oct 3 10:38:14 SymantecServer: Administrative Log Syslog header removed, but when sent over syslog these lines typically Log samplesīelow are samples of some different SEP log types.

Logs exported to text file always begin with the event time and severityĬolumns (e.g. The default isĬ:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\data\dump\*.log. Read from the location where the log files are being written.

The data is mapped toĮCS fields where applicable and the remaining fields are written under Headers are allowed and will be parsed if present. The log message is expected to be in CSV format. To receive logs sent by SEP over syslog or read logs exported to a text file. This integration is for Symantec Endpoint Protection (SEP) logs.
