Symantec Endpoint Protection Manager Response Integration via API

Purpose

This guide explains how to configure the Symantec Endpoint Protection Manager (SEPM) Response integration in Logsign USO, so that Incidents and Alarms can automatically, or an analyst can manually, trigger a full or quick scan, quarantine/unquarantine an endpoint, and look up file fingerprints managed by SEPM. This is not a log collection poller: it is a Response (action) integration, configured under Settings > Integrations > Responses > +Device.

This is not the same product as Symantec Endpoint Protection (SEP) cloud console or Symantec Endpoint Security (SES). SEPM is Broadcom's on-premises management server for legacy Symantec Endpoint Protection deployments, with its own REST API and its own username/password authentication model, separate from SES's cloud-hosted, Client ID/Client Secret OAuth model. Use this guide only if your environment runs an on-premises SEPM console.

Prerequisites

  • An on-premises Symantec Endpoint Protection Manager console reachable from the Logsign server.
  • A SEPM account with API access. SEPM's REST API authenticates with a regular console username and password (optionally scoped to a specific Domain in multi-domain SEPM deployments).
  • Use least privilege. Create a dedicated SEPM administrator account for this integration rather than reusing a personal login, and scope it to the minimum role that allows scanning, quarantine, and fingerprint lookup if your SEPM version supports limited administrator roles. The exact role name was not independently verified against a live SEPM console during this research; confirm with your SEPM administrator.

Step 1: Prepare a SEPM Account for API Access

  1. Log in to the SEPM console with an administrator account.
  2. Create (or designate) a dedicated administrator account for Logsign to use, and note its username and password.
  3. If your SEPM deployment uses multiple Domains, note the Domain name the account belongs to; this is required as a separate field in Logsign's configuration.
  4. Note the base URL of your SEPM console (the hostname/port you use to reach the SEPM web console or its API endpoint).

Step 2: Configure the Integration in Logsign USO

In Logsign USO, go to Settings > Integrations > Responses, search for Symantec Endpoint Protection Manager, click Configure then +Device, and fill in:

FieldRequiredDescription
Device NameYesFree-text label identifying this SEPM device in Logsign.
UrlYesBase URL of your SEPM console.
UsernameYesThe SEPM account username from Step 1.
PasswordYesPassword for that account. Stored encrypted at rest.
DomainNoThe SEPM Domain the account belongs to, if your deployment uses multiple domains. Leave blank for a single-domain deployment.
Insecure Skip VerifyNoDisables TLS certificate validation on Logsign's outbound calls to SEPM when enabled. Leave off unless you have a specific reason (for example a self-signed certificate on an internal SEPM console) to keep it on.

Click Create to save the device.

Available Methods

  • full-scan (Containment) — triggers a full antivirus scan on the target host.
  • quick-scan (Containment) — triggers a quick antivirus scan on the target host.
  • quarantine-device (Containment) — isolates a device from the network.
  • unquarantine-device (Recovery) — releases a device from network quarantine.
  • get-fingerprints-with-name — looks up file fingerprint information by name.
  • get-fingerprints-with-id — looks up file fingerprint information by ID.

Troubleshooting

SymptomLikely causeWhat to check
401 UnauthorizedWrong username/password, or the account was disabled/locked in SEPM.Re-enter the Username and Password fields and confirm the account can still log in to the SEPM console directly.
403 ForbiddenThe account's SEPM role does not permit the action being called.Confirm the account's assigned role in SEPM Administrators settings covers scan, quarantine, and fingerprint-lookup actions.
Connection failure / timeoutWrong Url, wrong Domain, or network path from Logsign to SEPM is blocked.Confirm the Url points at the correct SEPM console, the Domain field matches the account's domain (if applicable), and outbound access from Logsign to SEPM is allowed.

Notes and Limits

  • This integration is specifically for on-premises Symantec Endpoint Protection Manager. It is unrelated to the separate Symantec Endpoint Protection (via API) log collection poller, Symantec Endpoint Security (SES) integration, and Symantec Advanced Threat Protection (ATP) response integration, each of which is a different Broadcom/Symantec product with its own authentication model; do not confuse them when choosing a device type.
  • The exact SEPM console navigation path and role-naming for API access were not independently verified against a live SEPM console during this research (not independently verified); the field names and method behavior above are taken directly from Logsign's integration code.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.