Symantec Endpoint Protection Manager External Logs
Symantec Endpoint Protection Manager (SEPM) 14.3 external-log records of one SEPM server: the comma-delimited Administrative, Policy and Agent Activity payloads SEPM sends to a syslog server, kept verbatim in event.original in the labelled layout of the Elastic symantec_endpoint fixtures, with the rest of the document following that integration. For teams that test SIEM parsing and detection. About 9,500 records a day from 60 clients and 12 administrators follow the working day in UTC. Recurring episodes show one administrator failing to log on several times, then succeeding and editing the same shared policy twice, reverting the change.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-symantec-sepm/generator.yml \
--id sepm \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| client-log-received | Agent Activity: The management server received the client log successfully | 81.1% of records | none |
| policy-downloaded | Agent Activity: The client has downloaded the policy successfully | 17.0% of records | none |
| policy-edited | Policy: Policy has been edited: Edited shared <type> policy: <name> | 0.74% of records | none |
| auto-upgrade-config-downloaded | Agent Activity: The client has downloaded the auto-upgrade configuration file successfully | 0.64% of records | none |
| admin-logon (success) | Administrative: Administrator log on succeeded | 0.38% of records | authentication |
| admin-logon (failure) | Administrative: Administrator log on failed (double space, as in the Elastic fixtures) | 0.05% of records | authentication |
| group-added | Administrative: Group '<name>' was added | 0.05% of records | none |
Realism Features
- About 9,500 records a day follow the working day in UTC: about 680 an hour from 08:00 to 18:00, about 320 at 07:00 and 18:00, and about 170 an hour at night. The 10 servers upload logs around the clock, about 8 uploads per server per hour; the 50 workstations in the Workstations, Finance and Sales groups are switched on from 07:00 to 19:00 UTC and upload about 9 times an hour each, and at night only about 10 of them, a different set each night, stay on. About one upload in 125 is an auto-upgrade configuration download instead, roughly one per client per day.
- Twelve administrators work console sessions on their own schedules: the time between sessions is lognormal in working hours with a per-account median of 1.25 to 9 hours, and about 3% of administrator records fall between 20:00 and 07:00. Four busy accounts log on about 4 to 7 times a day, the others once or twice. 7% of first log-on attempts fail and 35% of retries after a failure fail too (about one attempt in ten fails); retries follow seconds to minutes later, the administrator gives up after 10% of failures, and five failures in a row lock the account for 15 minutes, with the next attempt after the lockout. The console writes no logout record.
- After a successful log-on a quarter of sessions end without an operation; otherwise operations follow a few seconds to 20 minutes apart, each followed by another with probability 0.6. An operation edits one of eight shared policies, or in 7% of cases adds a group; each administrator prefers a few policies, and about a third of edits edit the same policy again in the same session.
- Every client in a group assigned to an edited policy downloads it once, even after several edits: 75% within five minutes and 92% within ten, the rest, which were offline, minutes to hours later; workstations switched off at night download it after they are switched on in the morning. Agent Activity records do not name the downloaded policy, so downloads link to an edit only through time and the policy's groups.
- Every chain step also occurs in background on its own and in partial sequences: log-ons with two or more failures followed by a success (a few per week), edits of a policy the same administrator edited within the past hour (20 to 30 a day) and failures without a following success. With anomaly_mode on, each episode adds one such log-on sequence (about one a day at the default interval) and one more session for its administrator that day.
- Field order follows Broadcom KB 155205; the labelled layout and the exact policy-edit and failed log-on strings are copied from the Elastic integration fixtures. Wording for policy types other than Intrusion Prevention is inferred; policy add or delete, logout, System logs and all client-side logs (scan, risk, traffic, security) are not generated.
- No syslog header, dump-file time stamp or severity columns are emitted; @timestamp is the receive time in UTC with milliseconds, and the working day is fixed at 08:00-18:00 UTC with no weekends or holidays. Records the server writes at the same moment are seconds apart instead of milliseconds, a burst of policy downloads spreads over a few minutes, and log-on retries are about 18 seconds apart at the median. As in the Elastic pipeline, event.category and event.outcome are set only for log-on records; event.action is added for convenience.
- Log-on records carry no source address, so the chain links by account only; policy records do not show what changed, so the revert is inferred from the repeated edit. Rates and mixes are synthetic workload choices; no recording from a live SEPM server was available for comparison, and compatibility with the KUMA 4.2 Symantec normalizer is not verified.
Sample Output
{
"@timestamp": "2026-09-07T09:43:32.311Z",
"ecs": {
"version": "8.11.0"
},
"event": {
"action": "policy-edited",
"dataset": "symantec_endpoint.log",
"kind": "event",
"original": "Site: Site HQ-SEPM01,Server: HQ-SEPM01,Domain: Default,Admin: msmith,Event Description: Policy has been edited: Edited shared Firewall policy: Workstations Firewall Policy,Workstations Firewall Policy",
"provider": "Policy Log"
},
"message": "Policy has been edited: Edited shared Firewall policy: Workstations Firewall Policy",
"symantec_endpoint": {
"log": {
"admin": "msmith",
"domain_name": "Default",
"event_description": "Policy has been edited: Edited shared Firewall policy: Workstations Firewall Policy",
"policy_name": "Workstations Firewall Policy",
"server": "HQ-SEPM01",
"site": "Site HQ-SEPM01"
}
},
"user": {
"domain": "Default",
"name": "msmith"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include periodic anomaly episodes; false gives background only |
| anomaly_interval_hours | 24 | Hours between episode starts, 6 to 8,760; other values fail validation |
| site_name | Site HQ-SEPM01 | SEPM site name (Site: field) |
| server_name | HQ-SEPM01 | SEPM server name (Server: / Server Name: field) |
| sepm_domain | Default | SEPM domain (Domain: / Domain Name: field) |
| machine_domain | corp.contoso.com | Client machine domain, the last Agent Activity field |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.