You notice that the Symantec Endpoint Detection and Response (SEDR) appliance is still receiving events from a client after the client has been unenrolled from the SEDR appliance.
SEDR 4.10
The Symantec EDR will continue to accept endpoint activity logs from unenrolled clients until the clients receive an updated SEPM policy that removes the Symantec EDR enrollment information.
This is expected behavior and it may take up to one SEPM heartbeat cycle for SEP clients to unenroll completely from Symantec EDR. Until the policy is updated, clients might continue sending endpoint activity logs, policies, and command requests to Symantec EDR.