How Does One Offload Logs from Symantec Endpoint Security?
search cancel

How Does One Offload Logs from Symantec Endpoint Security?

book

Article ID: 244501

calendar_today

Updated On:

Products

Endpoint Security

Issue/Introduction

Administrators need a method to forward logs from the Symantec Endpoint Security console in the Cloud. 

Environment

Symantec Endpoint Security (SES) in the Cloud.

Cause

Contemporary models for forensic investigations and troubleshooting require access to high quality log data, including security event and incident management tool sets. Where the on-premise product provided a method for administrators to offload logs from the on-premise console, the administrators using the Cloud equivalent console need a method for offloading similar log data.

Resolution

Administrators over a SES environment can offload log data using the 'Event Export' option of the Security Cloud API.

Please reference https://apidocs.securitycloud.symantec.com/#/doc?id=ses_event_export

Additional Information

Support recommends the use of a reputable JSON events testing tool such as Postman for testing APIs.