About The Device
Symantec Endpoint Protection is a client-server solution that protects laptops, desktops, and servers in your network against malware, risks, and vulnerabilities. Symantec Endpoint Protection combines virus protection with advanced threat protection to proactively secure your client computers against known and unknown threats, such as viruses, worms, Trojan horses, and adware. Symantec Endpoint Protection provides protection against even the most sophisticated attacks that evade traditional security measures, such as rootkits, zero-day attacks, and spyware that mutates.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Broadcom (Previously as Symantec) |
Product Name | Symantec Endpoint Security Complete (Older Name: SEP 15/SEP Cloud) |
Type of Device | Cloud |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log Collection Method | Data Source |
---|---|---|---|---|
Symantec Event export | SYMANTEC_EVENT_EXPORT | JSON | C2C | https://cloud.google.com/chronicle/docs/reference/feed-management-api#symantec-event-export |
Device Configuration
Sign in to the SEP 15/14.2 console.
Select Integration.
Click Client Application and copy the Customer ID and Domain ID, which are used when you create a Chronicle feed.
Click + Add and provide an application name.
Click Add and provide name.
Navigate to the Details page and perform the following actions:
In the Devices Group Management section, select View.
In the Alerts & Events Rule Management section, select View.
In the Investigation Incident section, select View.
Click Save.
Click the menu (vertical ellipses) located at the end of the application name and click Client Secret.
Copy the CLIENT ID, CLIENT SECRET & OAUTH CREDENTIALS (OAUTH REFRESH TOKEN), which are required when you configure the Chronicle feed.
Integration Parameters
Parameter Display Name | Default Value | Description |
---|---|---|
OAUTH TOKEN ENDPOINT | N/A | The endpoint to retrieve the OAuth token. |
OAUTH CLIENT ID | N/A | The OAuth client ID. |
OAUTH CLIENT SECRET | N/A | The OAuth client secret. |
OAUTH REFRESH TOKEN | N/A | An OAuth 2.0 token used to refresh access tokens when they expire. Provide “OAUTH CREDENTIALS“ which will be your “OAUTH REFRESH TOKEN“ |