Endpoint Protection

 View Only

  • 1.  SEP 16 does not report Network Intrusion audit log information that SEP 14 did.

    Posted May 05, 2026 11:47 AM

    We were auto upgraded to SEP 16 and have since lost report of Network Intrusion audit log information such as blocked malicious scan attempts. After sessions with support we determined that the new agent is working fine it just seems the new version 16 no longer reports on audit threats that we were used to getting in reports with SEP 14. Given this we are considering rolling back to version 14 on some public facing systems however if version 14 will be phased out in the near future this would be pointless. There does not seem to be a published time-frame on if version 14 will eventually be fully replaced by version 16.



    -------------------------------------------


  • 2.  RE: SEP 16 does not report Network Intrusion audit log information that SEP 14 did.

    Broadcom Employee
    Posted May 06, 2026 12:31 AM
    Edited by Russ_V May 06, 2026 12:35 AM

    Hello, 

    Thanks for using the Broadcom Community. 

    I understand your point.  

    For more information about SEP client versions end-of-service dates take a look at: ( End of Service column)
    https://knowledge.broadcom.com/external/article/154575, if no end-of-service date is listed then you're good.  

    NOTE: The source of truth is stored here when in doubt: 
    https://knowledge.broadcom.com/external/article/150550/product-lifecycle-and-end-of-life-inform.html.

    Separately, in SEP16 the Scan, Risk, and Packet Logs were consolidated into the other logs available.  Please see the techdocs link below to help identify which client log has your desired events on the client side and then take another look at the SES Cloud report template specific to that log type. 
    - https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-security/sescloud/about-esa-sep/reviewing-sea-logs.html

    If you still don't see the relevant logs you were expecting, please let me know.

    It would also be helpful if you could provide a specific example of what logging you had in SEP 14.x reporting that you're missing.  

    Thanks,

    Russ_V

    -------------------------------------------



  • 3.  RE: SEP 16 does not report Network Intrusion audit log information that SEP 14 did.

    Posted May 07, 2026 01:19 PM

    We had the same issue, and it was due to the Feature Selection Policy not having Firewall and Intrusion Prevention selected for Servers.  Once we enabled those and a LiveUpdate was run, the IPS and Firewall were activated for the servers, and the alerts began showing up again.

    -------------------------------------------



  • 4.  RE: SEP 16 does not report Network Intrusion audit log information that SEP 14 did.

    Posted May 08, 2026 10:32 AM

    Really appreciate you taking the time to reply as this was the information we needed. I failed to notice that Defender was turned back on in the upgrade and assumed all the policies and settings would auto migrate. This solves it and hope it makes it's way into the "Recommended Upgrade Tasks" section of the published upgrade TechDoc.

    -------------------------------------------



  • 5.  RE: SEP 16 does not report Network Intrusion audit log information that SEP 14 did.

    Posted May 11, 2026 12:27 PM

    Hi -

    We experienced the same issue, and after troubleshooting, we found that the "Feature Selection Policy" for the server groups didn't have the "Intrusion Prevention" or "Firewall" options selected under "Server".

    Once we enabled them and pushed a Live Update, the appropriate engines/policies were loaded, and the blocks started occurring again.  No server restarts required.

    -------------------------------------------