Athena EPP (formerly Sangfor Endpoint Secure) integrates NGAV, EDR, and endpoint management into a single, powerful solution for comprehensive endpoint protection.
In the Data Sync module, you can configure the Athena EPP manager to send data such as logs and asset information to a third-party syslog server or Kafka server.
4.7.8.1 Syslog Reporting
On this page, you can configure settings to synchronize the logs of Athena EPP to a syslog server over the syslog protocol, as shown in the following figure.
Protocol: First, select the protocol supported by the syslog server. Most syslog servers support the UDP protocol. Then, specify the IP address and port of the syslog server.
Log Type: Select the types of logs to be synchronized to the syslog server.
Encoding Format: The Unicode, UTF-8, and GBK formats are supported.
Sync Mode: If you select Key Info, only a few log fields will be synchronized. This mode is suitable for log retention of the Multi-Level Protection Scheme (MLPS). If you select All Info, all log fields will be synchronized. This mode is suitable for a comprehensive security log analysis after synchronization.
4.7.8.2Kafka Reporting
On this page, you can configure settings to synchronize the logs of Athena EPP to a third-party Kafka server, as shown in the following figure.
Peer Cluster IP Address: Specify the IP address and port of the Kafka server. Example: 2.2.2.2:9092.
Authentication: Specify the Kafka server authentication method.
Agent Log Reporting: Specify the topic name and partition for storing the Athena EPP agent logs on the Kafka server.
Asset Info Reporting: Specify the topic name and partition for storing asset information on the Kafka server.