<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Questions about Add on for Symantec Endpoint Security (Cloud based- API integration required)? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Questions-about-Add-on-for-Symantec-Endpoint-Security-Cloud/m-p/595267#M76709</link>
    <description>&lt;P&gt;Hi Team&lt;/P&gt;
&lt;P&gt;Currently Splunk offers the 3.3.0 Add on for Symantec Endpoint Protection (aka SEP), this is an onpremise product, but Symantec also has a completely Cloud based solution called Endpoint Security&amp;nbsp; (aka SES) that requires an integration with an API, I would like to know how Splunk is managing this kind of integration, my questions are:&lt;/P&gt;
&lt;P&gt;1. Is there an Add on available that enables Splunk to collect data from the SES Cloud-API?&lt;/P&gt;
&lt;P&gt;2. If not,&amp;nbsp; What is the recommendation from Splunk to address the SES logs into the SIEM?&lt;/P&gt;
&lt;P&gt;3. When is going to be available an agent even for a intermediate connection?&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jul 2022 13:56:38 GMT</pubDate>
    <dc:creator>rcalvo_ilt</dc:creator>
    <dc:date>2022-07-22T13:56:38Z</dc:date>
    <item>
      <title>Questions about Add on for Symantec Endpoint Security (Cloud based- API integration required)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Questions-about-Add-on-for-Symantec-Endpoint-Security-Cloud/m-p/595267#M76709</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;
&lt;P&gt;Currently Splunk offers the 3.3.0 Add on for Symantec Endpoint Protection (aka SEP), this is an onpremise product, but Symantec also has a completely Cloud based solution called Endpoint Security&amp;nbsp; (aka SES) that requires an integration with an API, I would like to know how Splunk is managing this kind of integration, my questions are:&lt;/P&gt;
&lt;P&gt;1. Is there an Add on available that enables Splunk to collect data from the SES Cloud-API?&lt;/P&gt;
&lt;P&gt;2. If not,&amp;nbsp; What is the recommendation from Splunk to address the SES logs into the SIEM?&lt;/P&gt;
&lt;P&gt;3. When is going to be available an agent even for a intermediate connection?&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 13:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Questions-about-Add-on-for-Symantec-Endpoint-Security-Cloud/m-p/595267#M76709</guid>
      <dc:creator>rcalvo_ilt</dc:creator>
      <dc:date>2022-07-22T13:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Add on for Symantec Endpoint Security (Cloud based- API integration required)</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Questions-about-Add-on-for-Symantec-Endpoint-Security-Cloud/m-p/606659#M77239</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I dealt with the identical issue. The only viable solution is to call an API. Or purchase Symantec's log parser exchange with a syslog output for SIEMS. This is purposely done.&lt;/P&gt;&lt;P&gt;You can do so by following these steps: &lt;A href="https://apidocs.securitycloud.symantec.com/#/doc?id=ses" target="_blank"&gt;https://apidocs.securitycloud.symantec.com/#/doc?id=ses&lt;/A&gt; auth&lt;/P&gt;&lt;P&gt;Generate an OAuth Key from the Symantec console in order to generate a bearer token with an expiration time for API calls. You have multiple alternatives, including Export Events and Export Stream Events, among others. The "Heavy Forwarder" server was what I used to execute these orders. The data can then be saved in a text file and parsed as desired.&lt;/P&gt;&lt;P&gt;You can also design the Add-On yourself, but then you're responsible for its maintenance and updates... so it's not worth it.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 13:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Questions-about-Add-on-for-Symantec-Endpoint-Security-Cloud/m-p/606659#M77239</guid>
      <dc:creator>jo54</dc:creator>
      <dc:date>2022-07-22T13:39:10Z</dc:date>
    </item>
  </channel>
</rss>

