Endpoint Protection

 View Only
  • 1.  Audit/Monitoring

    Posted Jun 07, 2013 12:45 AM

    Hello.  Does SEPM 12.1+ console include the ability to track administrator/user accesses directly into the console by way of access logs?

     

    Thanks!

    jdk1965



  • 2.  RE: Audit/Monitoring

    Broadcom Employee
    Posted Jun 07, 2013 01:01 AM

    Audit log should be helpful



  • 3.  RE: Audit/Monitoring

    Posted Jun 07, 2013 01:05 AM

    Yes you can check in the logs

    SEPM click on ,monitors- logs -

    Log type :system-

    Log content:adminstrative logs

    Which administrator activities are logged in the Symantec Endpoint Protection Manager console?

    http://www.symantec.com/docs/TECH141668

     



  • 4.  RE: Audit/Monitoring

    Posted Jun 07, 2013 01:32 AM

    Check Mithun Comments

    https://www-secure.symantec.com/connect/forums/sepm11-audit-logs#comment-8175431



  • 5.  RE: Audit/Monitoring



  • 6.  RE: Audit/Monitoring

    Posted Jun 07, 2013 04:58 AM

    HI, 

    Follow the Steps 

    Admin Logs.jpg

    Regards

    Ajin

     



  • 7.  RE: Audit/Monitoring

    Broadcom Employee
    Posted Jun 07, 2013 10:01 AM

    Hi,

    Thank you for posting in Symantec connect.
     
    I would be glad to answer your question.
     
    You can view only activities and event logs with the help of this article with some limitations.

    Which administrator activities are logged in the Symantec Endpoint Protection Manager console?

    http://www.symantec.com/docs/TECH141668

    Idea has been raised to log more information, can promote this idea.

    Idea: Have more details in the logs regarding computer accounts moved/copied/deleted events

    https://www-secure.symantec.com/connect/ideas/have-more-details-logs-regarding-computer-movedcopieddeleted-events

     



  • 8.  RE: Audit/Monitoring

    Trusted Advisor
    Posted Jun 14, 2013 02:04 PM

    Hello,

    The Audit log contains information about policy modification activities, such as the event times and types, policy modifications, domains, sites, administrators, and descriptions.

    The default Audit quick report is called Policies Used. View the Policies Used report to monitor the policies in use in your network, by group. You can look at the Audit log when you want to see which administrator changed a particular policy and when.

    About the reports you can run

    Check these Articles:

    About log types

    http://www.symantec.com/docs/HOWTO27271

    About Computer Status reports and logs

    http://www.symantec.com/docs/TECH95541

    About the different types of Symantec Endpoint Protection Manager Reports

    http://www.symantec.com/docs/TECH95538

    Which administrator activities are logged in the Symantec Endpoint Protection Manager console?

    http://www.symantec.com/docs/TECH141668

    Hope that helps!!