To configure System Endpoint Protection Logging to send logs to the Comm Broker Sender:
In the Symantec console, click Admin.
Click Servers.
Select the local or remote site for which you want to configure external logging.
Under Tasks, click Configure External Logging.
On the General tab, select how often you want log data to be sent.
Select the Master Logging server that you want to handle external logging. If you use Microsoft SQL with more than one management server connecting to the database, only one server needs to be a Master Logging Server.
Check Enable Transmission of Logs to a Syslog Server.
In the Syslog Server box, type the IP address or hostname of the Comm Broker Sender. The Destination Port information should be
UDPand514(default).Click OK.
Default settings on the Log Filter tab are set to send all logs. If you run into performance issues, you can scale this back to send only relevant events.