When configuring external logging in the Symantec Endpoint Protection Manager (SEPM) for a Syslog server using a TCP port other than the default port of 1468, the manager will not change the port setting and reverts back to the default TCP port of 1468
An administrator attempts to configure external logging in SEPM for Syslog server. They want to configure the logging to be sent by TCP 514 and enters this in the SEPM. The administrator clicks Okay and then reopens the GUI and it reflects TCP 1468, even though he sees the traffic on TCP 514 from SEPM to Syslog.
Though the SEPM does not reflect that the port has changed, the save is successfully stored in the Database. Even though the SEPM will indicate that the port in use is TCP 1468, the syslog server will be forwarded information over port TCP 514. The issue is cosmetic only.