<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to Ingest Trellix ePO Logs into Splunk in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703004#M11734</link>
    <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm currently working on integrating Trellix ePolicy Orchestrator (ePO) logs into Splunk for better monitoring and analysis. I would like to know the best approach to configure Splunk to collect and index logs from the Trellix ePO server.&lt;/P&gt;&lt;P&gt;Specifically, I’m looking for details on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Recommended methods (e.g., syslog, API, or other tools/add-ons)&lt;/LI&gt;&lt;LI&gt;Any Splunk add-ons or apps that facilitate ePO log ingestion&lt;/LI&gt;&lt;LI&gt;Best practices for configuration and parsing these logs in Splunk&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any guidance or references to documentation would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 29 Oct 2024 13:24:01 GMT</pubDate>
    <dc:creator>refahiati</dc:creator>
    <dc:date>2024-10-29T13:24:01Z</dc:date>
    <item>
      <title>How to Ingest Trellix ePO Logs into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703004#M11734</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm currently working on integrating Trellix ePolicy Orchestrator (ePO) logs into Splunk for better monitoring and analysis. I would like to know the best approach to configure Splunk to collect and index logs from the Trellix ePO server.&lt;/P&gt;&lt;P&gt;Specifically, I’m looking for details on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Recommended methods (e.g., syslog, API, or other tools/add-ons)&lt;/LI&gt;&lt;LI&gt;Any Splunk add-ons or apps that facilitate ePO log ingestion&lt;/LI&gt;&lt;LI&gt;Best practices for configuration and parsing these logs in Splunk&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any guidance or references to documentation would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 29 Oct 2024 13:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703004#M11734</guid>
      <dc:creator>refahiati</dc:creator>
      <dc:date>2024-10-29T13:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ingest Trellix ePO Logs into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703353#M11736</link>
      <description>&lt;P&gt;There is a Splunk-supported TA for McAfee ePO&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/5085" target="_blank"&gt;https://splunkbase.splunk.com/app/5085&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The log ingestion is via syslog (as far as I remember from few years back, ePO exports event over TLS-protected TCP stream). The rest you'll find in the docs - it's a Splunk-supported app so it has relatively good docs.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 21:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703353#M11736</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-01T21:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ingest Trellix ePO Logs into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703588#M11737</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Thank you for the information!&lt;/P&gt;&lt;P&gt;Currently, I'm receiving logs from the ePO server via Syslog, but the logs aren’t being received in full. To improve this, I’m considering using the ePO API for more reliable log collection. Could you guide me on how to configure log ingestion from the ePO server using its API instead of Syslog?&lt;/P&gt;&lt;P&gt;I would appreciate details on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Steps for setting up ePO API integration with Splunk&lt;/LI&gt;&lt;LI&gt;Any authentication requirements or best practices for secure data transfer&lt;/LI&gt;&lt;LI&gt;Example scripts or configurations, if available&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thank you in advance for any guidance!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Nov 2024 10:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703588#M11737</guid>
      <dc:creator>refahiati</dc:creator>
      <dc:date>2024-11-05T10:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to Ingest Trellix ePO Logs into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703591#M11738</link>
      <description>&lt;P&gt;Can't help you here beyond advising again to check the docs. Haven't dealt with ePO for several years now.&lt;/P&gt;&lt;P&gt;If by "logs aren't received in full" you mean that events are truncated, you're probably trying to send them over UDP and then you are limited by the maximum UDP datagram length. Switch to TCP (again - as far as I remember, ePO requires TLS encryption over TCP so it might be a little more tricky to configure) and you're all set.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 11:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-Ingest-Trellix-ePO-Logs-into-Splunk/m-p/703591#M11738</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-05T11:30:51Z</dc:date>
    </item>
  </channel>
</rss>

