> ## Documentation Index
> Fetch the complete documentation index at: https://docs.threataware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Symantec Endpoint Protection

> Connect ThreatAware to Symantec Endpoint Protection to integrate data and enhance your security monitoring capabilities

## Overview

The Symantec Endpoint Protection integration enables ThreatAware to collect data from Symantec Endpoint Protection, providing enhanced visibility and security controls.

<Info>
  **Connection Method**: API
  **Setup Time**: 15 minutes
  **Access Required**: Administrator account
</Info>

## Setup instructions

### Authorization/setup steps

1. **Log in to ThreatAware**:
   * Access the ThreatAware dashboard and navigate to **Settings → Integrations**.
2. **Locate Symantec Endpoint Protection Manager (SEPM)**:
   * Use the search bar to find **Symantec Endpoint Protection Manager**.
3. **Configure Firewall Rules**:
   * Set up an inbound rule to allow access only from ThreatAware’s current allowlist IPs, available in-product under **Settings → Integrations → AWS Account / IP Whitelist Info**
   * Forward traffic from an external port (e.g., `8446`) to SEPM’s internal port for web services.
   * Use the external IP of the hosting location to forward traffic to SEPM’s internal IP.
4. **Create SEPM User Account**:
   * Log in to SEPM as an administrator.
   * Navigate to **Admin > Add an Administrator**.
   * In the **General** tab:
     * Define the username, full name, and email address.
   * Under **Access Rights**:
     * Assign the role **Limited Administrator**.
     * Specify the required permissions.
5. **Input Details in ThreatAware**:
   * Enter the following details in the integration form:
     * **Username**: SEPM account username.
     * **Password**: Password for the SEPM user account.
     * **External IP Address**: Publicly accessible IP of the SEPM server.
     * **Forwarded Port**: External port configured for SEPM.

### Important notes and links

* The integration requires strict control over firewall rules to ensure secure access.
* For detailed permissions and setup guidance, consult the Symantec Endpoint Protection Manager documentation.

### Input details

* **Username**: Username of the SEPM user account.
* **Password**: Password for the SEPM user account.
* **External IP Address**: Publicly accessible IP of the SEPM server.
* **Forwarded Port**: Port forwarded to the SEPM internal port.

### Verification and troubleshooting

* **Verification**: Confirm that the **Integration Status** in ThreatAware displays as **Active** after completing the setup.
* **Troubleshooting**:
  * **Invalid Credentials**: Verify the username and password for the SEPM user.
  * **Firewall Configuration Issues**: Ensure that firewall rules and port forwarding settings are correctly applied.
