{ 
    "id": "SymantecEndpointProtection",
    "title": "[Deprecated] Symantec Endpoint Protection", 
    "publisher": "Broadcom", 
    "descriptionMarkdown": "The [Broadcom Symantec Endpoint Protection (SEP)](https://www.broadcom.com/products/cyber-security/endpoint/end-user/enterprise) connector allows you to easily connect your SEP logs with Microsoft Sentinel. This gives you more insight into your organization's network and improves your security operation capabilities.", 
    "additionalRequirementBanner":"These queries are dependent on a parser based on a Kusto Function deployed as part of the solution.",
    "graphQueries": [ 
     { 
         "metricName": "Total data received", 
         "legend": "SymantecEndpointProtection", 
         "baseQuery": "SymantecEndpointProtection" 
     } 
    ], 
          "sampleQueries": [ 
           { 
               "description" : "Top 10 Log Types ", 
               "query": "SymantecEndpointProtection \n | summarize count() by LogType \n| top 10 by count_"    
           },
        {
            "description" : "Top 10 Users",
            "query": "SymantecEndpointProtection \n | summarize count() by UserName \n| top 10 by count_"
        }
        ], 
            "dataTypes": [ 
            { 
               "name": "Syslog (SymantecEndpointProtection)", 
               "lastDataReceivedQuery": "SymantecEndpointProtection \n            | summarize Time = max(TimeGenerated)\n            | where isnotempty(Time)" 
            } 
        ], 
             "connectivityCriterias": [ 
                { 
                    "type": "IsConnectedQuery", 
                    "value": [ 
                    "SymantecEndpointProtection \n      | where TimeGenerated > ago(3d)\n    |take 1\n        | project IsConnected = true" 
             ] 
                } 
            ], 
            "availability": { 
            "status": 1,
            "isPreview": false
            }, 
            "permissions": { 
            "resourceProvider": [ 
                   { 
                       "provider": "Microsoft.OperationalInsights/workspaces", 
                       "permissionsDisplayText": "write permission is required.", 
                       "providerDisplayName": "Workspace", 
                       "scope": "Workspace", 
                       "requiredPermissions": { 
                       "write": true, 
                       "delete": true 
                    } 
                } 
            ],
            "customs": [
                {
                    "name": "Symantec Endpoint Protection (SEP)",
                    "description": "must be configured to export logs via Syslog"
                }
            ]
    }, 
            "instructionSteps": [
                { 
                    "title": "", 
                    "description": "**NOTE:** This data connector depends on a parser based on a Kusto Function to work as expected which is deployed as part of the solution. To view the function code in Log Analytics, open Log Analytics/Microsoft Sentinel Logs blade, click Functions and search for the alias Symantec Endpoint Protection and load the function code or click [here](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Symantec%20Endpoint%20Protection/Parsers/SymantecEndpointProtection.yaml), on the second line of the query, enter the hostname(s) of your SymantecEndpointProtection device(s) and any other unique identifiers for the logstream. The function usually takes 10-15 minutes to activate after solution installation/update.",
                    "instructions": [ 
                    ]    
                },  
                { 
                    "title": "1. Install and onboard the agent for Linux", 
                    "description": "Typically, you should install the agent on a different computer from the one on which the logs are generated.\n\n>  Syslog logs are collected only from **Linux** agents.", 
                    "instructions": [ 
                        { 
                        "parameters": { 
                        "title": "Choose where to install the agent:", 
            "instructionSteps": [ 
                    { 
                    "title": "Install agent on Azure Linux Virtual Machine", 
                    "description": "Select the machine to install the agent on and then click **Connect**.", 
                    "instructions": [ 
                        { 
                        "parameters": { 
                        "linkType": "InstallAgentOnLinuxVirtualMachine" 
                        }, 
                        "type": "InstallAgent" 
                        } 
                    ]    
                }, 
                    { 
                    "title": "Install agent on a non-Azure Linux Machine", 
                    "description": "Download the agent on the relevant machine and follow the instructions.", 
                    "instructions": [ 
                        { 
                        "parameters": { 
                        "linkType": "InstallAgentOnLinuxNonAzure" 
                        }, 
                        "type": "InstallAgent" 
                        } 
                    ] 
                } 
            ] 
                }, 
                    "type": "InstructionStepsGroup" 
                    } 
                ] 
                    }, 
            { 
                    "title": "2. Configure the logs to be collected", 
                    "description": "Configure the facilities you want to collect and their severities.\n 1. Under workspace advanced settings **Configuration**, select **Data** and then **Syslog**.\n 2. Select **Apply below configuration to my machines** and select the facilities and severities.\n 3.  Click **Save**.",
                    "instructions": [
                        {
                            "parameters": { 
                                "linkType": "OpenSyslogSettings"
                            },
                            "type": "InstallAgent"
                        }
                    ]
                },
            {
                "title": "3. Configure and connect the Symantec Endpoint Protection",
                "description":"[Follow these instructions](https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-protection/all/Monitoring-Reporting-and-Enforcing-Compliance/viewing-logs-v7522439-d37e464/exporting-data-to-a-syslog-server-v8442743-d15e1107.html) to configure the Symantec Endpoint Protection to forward syslog. Use the IP address or hostname for the Linux device with the Linux agent installed as the Destination IP address."
            }
        ]
} 
