- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Supported OS
Symantec Endpoint Protection is a client-server solution that protects laptops, desktops, and servers in your network against malware, risks, and vulnerabilities. Symantec Endpoint Protection combines virus protection with advanced threat protection to proactively secure your client computers against known and unknown threats, such as viruses, worms, Trojan horses, and adware. Symantec Endpoint Protection provides protection against even the most sophisticated attacks that evade traditional security measures, such as rootkits, zero-day attacks, and spyware that mutates.
This integration enriches and ingests the following logs from Symantec Endpoint Protection:
client_server
activities.You can also visualize detailed insights into the above-mentioned logs with the out-of-the-box dashboards. Once you’ve installed the integration, you can find the dashboards by searching for “symantec-endpoint-protection” in the dashboards list.
To install the Symantec Endpoint Protection integration, run the following Agent installation command and the steps below. For more information, see the Integration Management documentation.
Note: This step is not necessary for Agent version >= 7.52.0.
Linux command:
sudo -u dd-agent -- datadog-agent integration install datadog-symantec_endpoint_protection==1.0.0
Collecting logs is disabled by default in the Datadog Agent. Enable it in datadog.yaml
:
logs_enabled: true
Add this configuration block to your symantec_endpoint_protection.d/conf.yaml
file to start collecting your Symantec Endpoint Protection logs.
See the sample symantec_endpoint_protection.d/conf.yaml for available configuration options.
logs:
- type: udp
port: <PORT>
service: symantec-endpoint-protection
source: symantec-endpoint-protection
Configure Syslog Message Forwarding from Symantec Endpoint Protection Server:
Run the Agent’s status subcommand and look for symantec_endpoint_protection
under the Checks section.
The Symantec Endpoint Protection integration collects audit, risk, scan, security, traffic, application control, and system logs.
The Symantec Endpoint Protection integration does not include any metrics.
The Symantec Endpoint Protection integration does not include any events.
The Symantec Endpoint Protection integration does not include any service checks.
If you see a Permission denied error while port binding in the Agent logs, see the following instructions:
Binding to a port number under 1024 requires elevated permissions. Grant access to the port using the setcap
command:
Grant access to the port using the setcap
command:
sudo setcap CAP_NET_BIND_SERVICE=+ep /opt/datadog-agent/bin/agent/agent
Verify the setup is correct by running the getcap
command:
sudo getcap /opt/datadog-agent/bin/agent/agent
With the expected output:
/opt/datadog-agent/bin/agent/agent = cap_net_bind_service+ep
Note: Re-run this setcap
command every time you upgrade the Agent.
Make sure that traffic is bypassed from the configured port if the firewall is enabled.
If you see the Port <PORT-NO> Already in Use error, see the following instructions. The example below is for PORT-NO = 514:
On systems using Syslog, if the Agent listens for Cisco Secure Firewall logs on port 514, the following error can appear in the Agent logs: Can't start UDP forwarder on port 514: listen udp :514: bind: address already in use
.
This error occurs because by default, Syslog listens on port 514. To resolve this error, take one of the following steps:
Need help? Contact Datadog support.