<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Symantec email security.cloud to Splunk Cloud in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528336#M313</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I was hoping to hear that Symantec supports HEC or another way of forwarding logs, before taking the on-prem HF route.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 14:33:42 GMT</pubDate>
    <dc:creator>cnuguri_ncc</dc:creator>
    <dc:date>2020-11-06T14:33:42Z</dc:date>
    <item>
      <title>Symantec email security.cloud to Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528311#M311</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am looking to onboard Symantec email security.cloud &amp;nbsp;data to Splunk cloud, but the add-on seems not compatible/available on Splunk Cloud ( &lt;A href="https://splunkbase.splunk.com/app/3830/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3830/&lt;/A&gt; ), could someone please advise if there is another way ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose using an on-prem HF for the add-on and forward data Splunk could work, although trying to avoid on-prem components if it is possible to onboard directly from IDM.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;BR /&gt;Chaith&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 12:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528311#M311</guid>
      <dc:creator>cnuguri_ncc</dc:creator>
      <dc:date>2020-11-06T12:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec email security.cloud to Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528333#M312</link>
      <description>&lt;P&gt;The standard practice for onboarding data when a TA cannot be installed in Splunk Cloud is to use an on-prem heavy forwarder.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 13:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528333#M312</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-06T13:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec email security.cloud to Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528336#M313</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I was hoping to hear that Symantec supports HEC or another way of forwarding logs, before taking the on-prem HF route.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 14:33:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528336#M313</guid>
      <dc:creator>cnuguri_ncc</dc:creator>
      <dc:date>2020-11-06T14:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec email security.cloud to Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528341#M314</link>
      <description>&lt;P&gt;AFAIK, Symantec does not support HEC, but you could write your own program/script that reads Symantec data and converts it to HEC.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 15:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Symantec-email-security-cloud-to-Splunk-Cloud/m-p/528341#M314</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-06T15:39:40Z</dc:date>
    </item>
  </channel>
</rss>

