Overview
When configured, the Blumira integration with Symantec Endpoint Security will stream security event logs to the Blumira service for automated threat detection and actionable response. Forward traffic logs from Symantec Endpoint Security to a SIEM for long-term storage, compliance, audit, reporting, or legal reasons.
Before you begin
This integration requires a Blumira sensor to be installed before you can complete the steps below. Ensure that you complete the steps in Building a Blumira sensor with Ubuntu before you continue.
Gather the IP address of your Blumira sensor to use when configuring the external service.
To find and copy the IP address of the sensor, do the following:
- In Blumira, navigate to Settings > Sensors.
- Click the sensor row to open the details page.
- Under Overview, in the Host Details box, copy the IP value.
Configure log forwarding
To send logs to a Blumira sensor:
- In the Symantec Endpoint console, click Admin.
- Click Servers.
- Click the local site or remote site that you want to export log data from.
- Click Configure External Logging.
- On the General tab, in the Update Frequency list box, select how often to send the log data to the file.
- In the Master Logging Server list box, select the management server to send the logs to.
Note: If you use SQL Server and connect multiple management servers to the database, specify only one server as the Master Logging Server. - Select Enable Transmission of Logs to a Syslog Server.
- Provide the following information:
- In Syslog Server, type the IP address of the Blumira sensor that you want to receive the log data.
- In Destination Port, type the number of the log facility that you want to the Syslog configuration file to use, or use the default. Valid values range from 0 to 23.
- On the Log Filter tab, check which logs to export.
- Click OK.