This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Community Blog
Subscribe to the official NetWitness Community blog for information about new product features, industry insights, best practices, and more.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Blog
  • Integration of Symantec Endpoint Security with Netwitness Platform

Integration of Symantec Endpoint Security with Netwitness Platform

RachanaSR
Contributor RachanaSR Contributor
Contributor
Options
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Printer Friendly Page
  • Report Inappropriate Content
‎2023-05-09 08:54 AM

Endpoint security is the practice of securing entry point of end users such as desktops, laptops, mobile devices, servers, storage devices, and containers on the network or the cloud from all the threats and malicious actors. The Endpoint security approaches have evolved from using traditional antivirus software to highly advanced systems to protect and remediate complex malicious activities.

 

Symantec Endpoint Security is one such fully cloud-managed software suite that consists of anti-malware, intrusion prevention, behavioral isolation, Active Directory security, and Threat Hunter technologies to protect your endpoints against threats and targeted attacks. It generates alerts, incidents and events based on scans, policies, and rules. An event is generated when Symantec Endpoint Security detects that activity occurred on a device. An incident is a collection of one or more events that represent a significant risk or potential threat to the organization. Alerts can be triggered by a single event or multiple events.


Netwitness Platform XDR Integrates with Symantec Endpoint Security to collect events from the event stream in real-time  and EDR incidents from Symantec Endpoint Security.

 

 

Integration Model:

RachanaSR_0-1683634208212.png

 

To take advantage of this new capability of Symantec Endpoint Security Integration within NetWitness, please visit the link below and search for the terms below in NetWitness Live.

Configuration Guides:  Symantec Endpoint Security Events , Symantec Endpoint Security Incidents 

Collector Package on NetWitness Live: "Symantec Endpoint Security Events Log Collector Configuration" , "Symantec Endpoint Security Incidents Log Collector Configuration" 

Parser on NetWitness Live: symantec_endpointsecurity

 

Integration reference:

  • https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-security/sescloud/Integrations/Event-streaming-using-EDR.html
  • https://apidocs.securitycloud.symantec.com/#/doc?id=ses_about

 

 

 

 

 

 

  • Integration
  • plugin
  • Symantec Endpoint Security
  • symantec_endpointsecurity
  • symantec_es_events
  • symantec_es_incidents
3 Likes

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • Advanced HTTP and TLS Concepts (Video)
  • Using NetWitness to Detect Command and Control: SILENTTRINITY C2
  • FirstWatch Threat Spotlight – Remcos RAT
  • FirstWatch Threat Spotlight: The LockBit Conundrum - A Glimpse into Ransomware Warfare
  • Content Hygiene – Application Rule Alert Mapping Updates
  • Microsoft Azure Log Analytics workspace integration with Netwitness
  • FirstWatch Threat Spotlight: Cryptonite Ransomware
  • Deployment Inventory (Serial Numbers)
  • The History of APT10
  • Integration of Symantec Endpoint Security with Netwitness Platform
Labels
  • Announcements 63
  • Events 8
  • Features 11
  • Integrations 12
  • Resources 66
  • Tutorials 31
  • Use Cases 27
  • Videos 118
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.