Hub
Security

Symantec Endpoint Protection Manager External Logs

Symantec Endpoint Protection Manager (SEPM) 14.3 external-log records of one SEPM server: the comma-delimited Administrative, Policy and Agent Activity payloads SEPM sends to a syslog server, kept verbatim in event.original in the labelled layout of the Elastic symantec_endpoint fixtures, with the rest of the document following that integration. For teams that test SIEM parsing and detection. About 9,500 records a day from 60 clients and 12 administrators follow the working day in UTC. Recurring episodes show one administrator failing to log on several times, then succeeding and editing the same shared policy twice, reverting the change.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/security-symantec-sepm/generator.yml \
  --id sepm \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
client-log-receivedAgent Activity: The management server received the client log successfully81.1% of recordsnone
policy-downloadedAgent Activity: The client has downloaded the policy successfully17.0% of recordsnone
policy-editedPolicy: Policy has been edited: Edited shared <type> policy: <name>0.74% of recordsnone
auto-upgrade-config-downloadedAgent Activity: The client has downloaded the auto-upgrade configuration file successfully0.64% of recordsnone
admin-logon (success)Administrative: Administrator log on succeeded0.38% of recordsauthentication
admin-logon (failure)Administrative: Administrator log on failed (double space, as in the Elastic fixtures)0.05% of recordsauthentication
group-addedAdministrative: Group '<name>' was added0.05% of recordsnone

Realism Features

  • About 9,500 records a day follow the working day in UTC: about 680 an hour from 08:00 to 18:00, about 320 at 07:00 and 18:00, and about 170 an hour at night. The 10 servers upload logs around the clock, about 8 uploads per server per hour; the 50 workstations in the Workstations, Finance and Sales groups are switched on from 07:00 to 19:00 UTC and upload about 9 times an hour each, and at night only about 10 of them, a different set each night, stay on. About one upload in 125 is an auto-upgrade configuration download instead, roughly one per client per day.
  • Twelve administrators work console sessions on their own schedules: the time between sessions is lognormal in working hours with a per-account median of 1.25 to 9 hours, and about 3% of administrator records fall between 20:00 and 07:00. Four busy accounts log on about 4 to 7 times a day, the others once or twice. 7% of first log-on attempts fail and 35% of retries after a failure fail too (about one attempt in ten fails); retries follow seconds to minutes later, the administrator gives up after 10% of failures, and five failures in a row lock the account for 15 minutes, with the next attempt after the lockout. The console writes no logout record.
  • After a successful log-on a quarter of sessions end without an operation; otherwise operations follow a few seconds to 20 minutes apart, each followed by another with probability 0.6. An operation edits one of eight shared policies, or in 7% of cases adds a group; each administrator prefers a few policies, and about a third of edits edit the same policy again in the same session.
  • Every client in a group assigned to an edited policy downloads it once, even after several edits: 75% within five minutes and 92% within ten, the rest, which were offline, minutes to hours later; workstations switched off at night download it after they are switched on in the morning. Agent Activity records do not name the downloaded policy, so downloads link to an edit only through time and the policy's groups.
  • Every chain step also occurs in background on its own and in partial sequences: log-ons with two or more failures followed by a success (a few per week), edits of a policy the same administrator edited within the past hour (20 to 30 a day) and failures without a following success. With anomaly_mode on, each episode adds one such log-on sequence (about one a day at the default interval) and one more session for its administrator that day.
  • Field order follows Broadcom KB 155205; the labelled layout and the exact policy-edit and failed log-on strings are copied from the Elastic integration fixtures. Wording for policy types other than Intrusion Prevention is inferred; policy add or delete, logout, System logs and all client-side logs (scan, risk, traffic, security) are not generated.
  • No syslog header, dump-file time stamp or severity columns are emitted; @timestamp is the receive time in UTC with milliseconds, and the working day is fixed at 08:00-18:00 UTC with no weekends or holidays. Records the server writes at the same moment are seconds apart instead of milliseconds, a burst of policy downloads spreads over a few minutes, and log-on retries are about 18 seconds apart at the median. As in the Elastic pipeline, event.category and event.outcome are set only for log-on records; event.action is added for convenience.
  • Log-on records carry no source address, so the chain links by account only; policy records do not show what changed, so the revert is inferred from the repeated edit. Rates and mixes are synthetic workload choices; no recording from a live SEPM server was available for comparison, and compatibility with the KUMA 4.2 Symantec normalizer is not verified.

Sample Output

{
  "@timestamp": "2026-09-07T09:43:32.311Z",
  "ecs": {
    "version": "8.11.0"
  },
  "event": {
    "action": "policy-edited",
    "dataset": "symantec_endpoint.log",
    "kind": "event",
    "original": "Site: Site HQ-SEPM01,Server: HQ-SEPM01,Domain: Default,Admin: msmith,Event Description: Policy has been edited: Edited shared Firewall policy: Workstations Firewall Policy,Workstations Firewall Policy",
    "provider": "Policy Log"
  },
  "message": "Policy has been edited: Edited shared Firewall policy: Workstations Firewall Policy",
  "symantec_endpoint": {
    "log": {
      "admin": "msmith",
      "domain_name": "Default",
      "event_description": "Policy has been edited: Edited shared Firewall policy: Workstations Firewall Policy",
      "policy_name": "Workstations Firewall Policy",
      "server": "HQ-SEPM01",
      "site": "Site HQ-SEPM01"
    }
  },
  "user": {
    "domain": "Default",
    "name": "msmith"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueInclude periodic anomaly episodes; false gives background only
anomaly_interval_hours24Hours between episode starts, 6 to 8,760; other values fail validation
site_nameSite HQ-SEPM01SEPM site name (Site: field)
server_nameHQ-SEPM01SEPM server name (Server: / Server Name: field)
sepm_domainDefaultSEPM domain (Domain: / Domain Name: field)
machine_domaincorp.contoso.comClient machine domain, the last Agent Activity field

Related Generators