SymDaemon is the core process of the Symantec Endpoint Protection (SEP) for Macintosh client. It is responsible for scheduling tasks, communicating with the Symantec Endpoint Protection Manager (SEPM), and applying policies among other things. Use the following steps to generate detailed, debug level logging for the SymDaemon process of the SEP for Macintosh client.
NOTE: this is for the on-premises SEP for Mac only; there is no equivalent debug logging for the cloud-managed SES Mac client.
You have been asked by a Broadcom support engineer to provide a debug trace of the Symantec Endpoint Protection Manager SymDaemon process.
All supported Mac OS version 10.x to 12.x
SEP for Mac
Open terminal window and navigate to the SMC folder location—
For SEP 14.2 RU2 and newer:
cd /Library/Application\ Support/Symantec/Silo/MES/SMC
For SEP 14.2 RU1 MP2 and older:
cd /Library/Application\ Support/Symantec/SMC
The following instructions assume that this is the current directory.
To enable debug logging for current SEP for MAC clients:
sudo ./tools/SetSettings -ldebug
# NOTE: Use sudo ./tools/SetSettings -lengineer in SEP 14.0.x and older clients.
sudo cp com.symantec.trace.plist /Library/Preferences/
# the library file 'com.symantec.trace.plist' is attached at bottom of this article. use the command line or manually copy the file to /Library/Preferences/