You can use the syslog facility to log Enforcer messages. You can specify the following aspects:
IP address of the syslog server
Level of syslog entry
Authentication failure threshold
Alive message interval
To enable logging messages to the syslog for an Enforcer
In Symantec Endpoint Protection Manager, click Admin.
Under Servers, select the Enforcer group for which you want to enable logging to the syslog.
Under Tasks, click Edit Group Properties.
On the Logging tab, in the Syslog section, select among the following options:
Imported Document Id