I am using SEPM version i want to have complete logs when any usb storage devices ll attached to any system where SEP client installed . i tried but when i applied any policy like blocked or unblocked usb storages then it generate logs. But if i applied nothing for usb storage device and try to attached usb storage in the system then it can't generate any logs . Is this possible without applying any device control policy SEPM generate logs when any of usb storage device attached with the syste.
2: Can its possible in SEPM then when generate its gives information to the SEPM manager that this file is copied and these were other things in that usb storage devices.
your urgent response ll be highly appreciated
Noor, As you can see in the screenshot attached, the logging is a separate check-box independent of the actions (read, write & block, unblock). So this should work.
Under ADC policy choose continue processing other rules & choose logging as mentioned below.
Also the below links might help
Policy to LOG activity in a USB drive by Symantec Endpoint Protection (SEP)
How to configure Application Control in Symantec Endpoint Protection 11.0 : Configuring Application Control Policies
How to block users to perform download of files with specific extentions using Application and Device Control.
Nraj...I want run time logs of every activity performing on SEPM cleints and server although that storage device is blocked or unblocked.
If this is possible in SEPM then let me know
your urgent response is highly appreciated
Agree with NRaj. Thumb Up.