You have Symantec Endpoint Protection for Linux (SEPfL) clients that are Active Directory (AD) integrated. You expect these clients to show up in their respective imported organizational units (OUs) in Symantec Endpoint Protection Manager (SEPM). However, they show up in the Default group instead.
SEPfL 12.1 RU6 or higher
This is 'by design'. SEPfL clients can only be managed using groups that are manually defined in SEPM.