Endpoint Protection

 View Only
  • 1.  Sending logs to SEIM

    Posted Apr 06, 2020 01:19 PM
    Hello,

    I need to send logs to our SEIM (Helix) how do I set that up and what logs can I send over? We are running SEP14.x on prem but in AWS. Thanks


  • 2.  RE: Sending logs to SEIM

    Posted Apr 07, 2020 09:10 AM

    I have the same question - (but more interested in what logs NOT to send or what the log filter setting recommendations are and most importantly what to definitely not send in order to avoid overload problems.)

    In our case, We are looking to do the same thing in our on-prem enterprise environment. We want to eliminate any need for direct pulls from the SEP SQL server and instead push directly from SEPM to the (Helix)SIEM - and we are doing that by configuring external logging on the SEPM console using syslog. :

    1. Click on the "Admin" tab, then click on "Servers"
      1. Under Servers - click on the "Local Site - ……" for the environment
      2. Under Tasks – select "Configure External Logging"
      3. Under the "General" tab – configure the relevant settings by:
        1. Selecting the "Enable Transmission of Logs to a Syslog Server"
        2. Then select the "Log Filter" tab – configure which client (and server) logs to send (this is what we would like to know the best practice recommendations on).