Overview
The Symantec Endpoint Protection Manager (SEPM) integration enables ThreatAware to access your on-premises SEPM deployment, providing visibility into endpoint protection status, threat detection, and security posture across your organisation.Connection Method: API (On-Premises)
Setup Time: 30 minutes
Access Required: SEPM Administrator account
Network: Requires firewall configuration for AWS-to-SEPM communication
Data collected
The SEPM integration provides:- Endpoint protection status
- Threat detection events
- Security policy compliance
- Device security posture
Use cases
Endpoint Protection Monitoring
Monitor endpoint protection status across your organisation
Threat Detection
Track detected threats and malware on protected endpoints
Policy Compliance
Verify Symantec security policies are correctly applied
Security Incidents
Investigate and respond to endpoint security incidents
Setup overview
SEPM integration requires configuration in three areas:- Creating a dedicated SEPM administrator account for ThreatAware
- Configuring firewall rules to allow AWS infrastructure to communicate with SEPM
- Providing connection details to ThreatAware
Prerequisites
- SEPM deployed on-premises and accessible from the internet (or via VPN/proxy)
- SEPM Administrator account with permissions to add new administrators
- External IPv4 address and port for SEPM web services
- Firewall access to configure inbound rules
Network configuration
Firewall requirements
To enable ThreatAware (hosted in AWS) to communicate with your on-premises SEPM, configure firewall rules: Inbound Rules - Allow traffic from ThreatAware’s current allowlist IPs, available in-product under Settings → Integrations → AWS Account / IP Whitelist Info. External Port Mapping:- Map an external port (any available port) to SEPM’s internal web services port
- SEPM default internal port:
8446 - Example: External port
8446→ Internal IP192.168.1.50:8446
- External IPv4 address → SEPM internal IPv4 address
- Document both the external address and port for ThreatAware configuration
Setup instructions
1
Create SEPM Administrator Account
- Log into SEPM using an existing Administrator account
- Navigate to Admin in the SEPM console
- Click “Add an Administrator”
2
Configure Administrator Details
In the General Tab:
- Username: Create a unique username (e.g.,
threataware-admin) - Full Name: Enter a descriptive name (e.g., “ThreatAware Integration”)
- Email Address: Enter an administrative contact email
- Password: Create a strong password and store securely
3
Set Administrator Permissions
Under the Access Rights section:
- Select Limited Administrator (not Full Administrator)
- Configure specific permissions required for ThreatAware:
- Typically includes:
- View reports and events
- Access to threat information
- Device inventory access
- Avoid granting unnecessary permissions (follow least privilege principle)
- Typically includes:
- Save the administrator account
4
Configure Firewall Rules
On your network firewall:
- Create an inbound rule allowing traffic from ThreatAware’s current allowlist IPs (see Settings → Integrations → AWS Account / IP Whitelist Info)
- Configure port mapping:
- External port → SEPM internal port
8446
- External port → SEPM internal port
- Document the external IPv4 address and port for ThreatAware
- Test connectivity from an external location to verify access
5
Test SEPM Access
- Verify SEPM is accessible via the external IPv4 address and port
- Test the URL:
https://{external-ip}:{external-port} - Confirm the SEPM login page appears
- Note any SSL certificate warnings (may be expected for on-premises systems)
6
Configure in ThreatAware
Log into ThreatAware and navigate to Settings → Integrations:
- Search for and select Symantec Endpoint Protection Manager
- Enter the following credentials:
- Username: The SEPM administrator username created in Step 1
- Password: The password for the SEPM administrator account
- External IPv4 Address: The external IP address of SEPM
- External Port: The external port mapped to SEPM (typically
8446)
- Click Connect or Authorize to establish the integration
7
Verify Connection
- Check the integration status displays as Active
- Data collection will begin within 1 hour
- Verify SEPM endpoint data appears in ThreatAware
Required credentials
Username
Username
Field Name: SEPM Administrator Username
Type: String
Description: The username of the SEPM administrator account created for ThreatAwareExample:
threataware-admin or svc_threatawarePassword
Password
Field Name: SEPM Administrator Password
Type: Password (encrypted)
Description: The password for the SEPM administrator account
External IPv4 Address
External IPv4 Address
Field Name: SEPM External IPv4 Address
Type: String
Description: The external IPv4 address used to access SEPM from the internetFormat: Dotted IPv4 notation (e.g.,
203.0.113.42)
Note: This should be the publicly routable address configured on your firewallExternal Port
External Port
Field Name: SEPM External Port
Type: Number
Description: The external port mapped to SEPM’s internal web services portDefault:
8446 (mapped to internal SEPM port 8446)
Example: Enter 8446 or your custom external portVerification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings → Integrations in ThreatAware
- Confirm SEPM shows Active status
- Check the last sync timestamp
-
Verify Endpoint Data
- Wait 60 minutes for the initial data poll
- Search for a known protected endpoint in ThreatAware
- Verify SEPM protection status appears in device details
-
Test Security Data
- Create a test query to filter endpoints by protection status
- Verify threat detection data if available
- Confirm data matches SEPM Console
Troubleshooting
Invalid Credentials Error
Invalid Credentials Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify the Username and Password are correct
- Ensure the SEPM administrator account is active and not locked
- Confirm the account has not been disabled
- Test logging into SEPM directly with these credentials
- Verify the password was entered without extra spaces
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the External IPv4 Address and External Port are correct
- Test connectivity: Open
https://{external-ip}:{external-port}in a browser - Confirm firewall rules allow traffic from ThreatAware AWS IPs to your SEPM
- Check inbound rules for the four AWS IP addresses
- Verify the port mapping is correctly configured on your firewall
- Test from a different network to rule out local firewall issues
Firewall Configuration Issues
Firewall Configuration Issues
Symptoms: Integration connects intermittently or data collection failsSolutions:
- Verify ThreatAware’s current allowlist IPs are in the inbound firewall rule (see Settings → Integrations → AWS Account / IP Whitelist Info)
- Confirm the external port is correctly mapped to SEPM port
8446 - Check for any IP filtering or blocking policies
- Verify the firewall rule is enabled and has no time-based restrictions
- Review firewall logs for any blocked connections
Permission Errors
Permission Errors
Symptoms: Integration connects but cannot access endpoint dataSolutions:
- Verify the SEPM administrator account has “Limited Administrator” role
- Ensure permissions include:
- View reports and events
- Device inventory access
- Threat information access
- Check that the account has not been restricted or suspended
- Verify permissions have not been reduced since account creation
- Update permissions if needed and retry the connection
SSL Certificate Issues
SSL Certificate Issues
Symptoms: Connection fails with SSL/certificate warningSolutions:
- On-premises SEPM typically uses self-signed certificates
- This is expected and should not prevent integration
- Verify the certificate error is from SEPM, not a network issue
- If using a valid certificate, ensure it has not expired
- Confirm the external IPv4 address matches the certificate CN/SAN
- Contact your SEPM administrator if certificate issues persist
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no endpoint data appearsSolutions:
- Verify SEPM has protected endpoints with data to collect
- Check that the administrator account can access endpoint data in SEPM
- Confirm permissions have not been restricted or changed
- Wait additional time - first sync may take longer than 1 hour
- Review ThreatAware integration logs for error messages
- Contact ThreatAware support if data collection continues to fail
Security best practices
Additional resources
Symantec SEPM Documentation
Official Symantec SEPM documentation for API and administrator setup
ThreatAware Support
Contact ThreatAware support for integration assistance
Important notes
On-Premises Deployment
- SEPM integration requires network connectivity from ThreatAware infrastructure to your on-premises SEPM
- Firewall configuration is essential for successful integration
- External IPv4 address and port must be stable and consistently accessible
- Test connectivity before finalizing ThreatAware configuration