<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mcafee syslog-ng  connection in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/563155#M100337</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We had the same problem with rsyslog yesterday and found out that *.key file had no read access.&lt;/P&gt;&lt;P&gt;So from:&lt;/P&gt;&lt;P&gt;-rw-------&lt;/P&gt;&lt;P&gt;To:&lt;/P&gt;&lt;P&gt;-rw-r--r--&lt;/P&gt;&lt;P&gt;/Tomas&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 07:47:28 GMT</pubDate>
    <dc:creator>Tomas_K</dc:creator>
    <dc:date>2021-08-13T07:47:28Z</dc:date>
    <item>
      <title>Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/531578#M89419</link>
      <description>&lt;P&gt;Good afternoon,&amp;nbsp; I will like to set up Mcafee Epo to send data to syslog-ng. I have the Mcafee portion setup on to send data to the syslog server on port 6514. The problem that i'm having is that i not sure what needs to be done on the server (centos 7) side to establish the connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* The firewall is configured for the port used&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 18:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/531578#M89419</guid>
      <dc:creator>junier16</dc:creator>
      <dc:date>2020-12-01T18:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/531593#M89422</link>
      <description>&lt;P&gt;I'll presume the syslog server is independent of both the McAfee and Splunk servers.&amp;nbsp; The usual flow is EPO -&amp;gt; syslog -&amp;gt; Splunk.&amp;nbsp; Any or all three of those could be CentOS servers so at which point are you having the problem?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 20:32:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/531593#M89422</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-01T20:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/532239#M89490</link>
      <description>&lt;P&gt;when i click&amp;nbsp; on test connection after adding the registered server the connection failed, so im not able to connect syslog server with ePO ( i think is because tls required) . I also see that the Splunk Add on required syslog to work. Is there another way to get data from ePo to Splunk ?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 19:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/532239#M89490</guid>
      <dc:creator>junier16</dc:creator>
      <dc:date>2020-12-07T19:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/532243#M89492</link>
      <description>&lt;P&gt;I've been successful using Splunk DB Connect to pull information from the EPO database, but that was a while ago and things could have changed since then.&lt;/P&gt;&lt;P&gt;But let's back up a little.&amp;nbsp; Where are you when you click on "test connection"?&amp;nbsp; Have you checked your firewalls to make sure none are blocking the connections?&amp;nbsp; Which Splunk add-on are you talking about?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 21:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/532243#M89492</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-07T21:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/533975#M89657</link>
      <description>&lt;P&gt;I have been fighting this battle for a while now off and on.&lt;/P&gt;&lt;P&gt;ePO has different places to configure logging depending on the product and it's still not totally clear to me.&amp;nbsp; But from what I have found standard McAfee syslog (registered syslog server) and App Control (registered SolidCore syslog appear) to be CEF TLS Syslog.&amp;nbsp; The "default" port is 6514 as you mention.&amp;nbsp; That means that you need to have a certificate on your syslog server on 6514TCP.&amp;nbsp; For further information check out some light reading of standards IETF&amp;nbsp;5424 + 5425.&amp;nbsp; DLP is different, but looks like it may work with the same setup.&amp;nbsp; That's because it can be UDP (which can be without TLS) or TCP.&lt;/P&gt;&lt;P&gt;Then you need to have some form to monitor the syslog collection to get it to your Splunk server.&amp;nbsp; The easiest way to do that is to have the forwarder monitor on the system and send it over.&amp;nbsp; If that's the case you probably want to add the &lt;SPAN&gt;Splunk Add-on for McAfee ePO Syslog&amp;nbsp;&lt;/SPAN&gt;on to your forwarder along with the sourcetype to ease the burden on your indexer.&lt;/P&gt;&lt;P&gt;We use a product called NXLog for now, and with the app&amp;nbsp;&lt;SPAN&gt;McAfee ePO Syslog app, we are able to collect and parse with the sourcetype mcafee:epo:syslog.&amp;nbsp; It looks kind of ugly in the raw event, but the fields seem to be parsed perfectly, which is the important&amp;nbsp;thing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For DLP we are going to see what's best DBConnect or syslog.&amp;nbsp; If you use DBConnect you have to basically reverse engineer the fields using querys&amp;nbsp;provided by ePO as the fields change from version to version.&amp;nbsp; Hopefully they will standardize that in the coming releases because seems to be awfully tedious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Tony&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 18:08:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/533975#M89657</guid>
      <dc:creator>tlay</dc:creator>
      <dc:date>2020-12-23T18:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/536700#M89969</link>
      <description>&lt;P&gt;Can you share you conf file statement that you used ?&amp;nbsp; Im using the below statement with the the cert, but syslog is not listening to the port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;source source_6514_tls {
tcp(port(6514)
tls(
key-file("/etc/syslog-ng/cert.d/server.key")
cert-file("/etc/syslog-ng/cert.d/server.crt")
peer-verify(optional-untrusted)
)
flags(no-multi-line)
);
};

destination dest_6514_local { file("/var/log/syslog/logs"); };

log {source(source_6514_tls); destination(dest_6514_local); };&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Jan 2021 14:48:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/536700#M89969</guid>
      <dc:creator>junier16</dc:creator>
      <dc:date>2021-01-21T14:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/554106#M91837</link>
      <description>&lt;P&gt;Did you ever get the config correct?&amp;nbsp; I need the same thing and am not having any success with the right configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 14:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/554106#M91837</guid>
      <dc:creator>leejones1964</dc:creator>
      <dc:date>2021-06-02T14:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/554359#M91872</link>
      <description>&lt;P&gt;no i never did. I used DBconnect to ingest the events&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 20:05:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/554359#M91872</guid>
      <dc:creator>junier16</dc:creator>
      <dc:date>2021-06-03T20:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/563155#M100337</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We had the same problem with rsyslog yesterday and found out that *.key file had no read access.&lt;/P&gt;&lt;P&gt;So from:&lt;/P&gt;&lt;P&gt;-rw-------&lt;/P&gt;&lt;P&gt;To:&lt;/P&gt;&lt;P&gt;-rw-r--r--&lt;/P&gt;&lt;P&gt;/Tomas&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 07:47:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/563155#M100337</guid>
      <dc:creator>Tomas_K</dc:creator>
      <dc:date>2021-08-13T07:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/563177#M100341</link>
      <description>&lt;P&gt;Did changing the permission for .key solved the issue ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 12:55:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/563177#M100341</guid>
      <dc:creator>junier16</dc:creator>
      <dc:date>2021-08-13T12:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Mcafee syslog-ng  connection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/563198#M100347</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes it did! We are up and running. At least Test connection and Eicar test event.&lt;/P&gt;&lt;P&gt;/Tomas&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 14:13:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mcafee-syslog-ng-connection/m-p/563198#M100347</guid>
      <dc:creator>Tomas_K</dc:creator>
      <dc:date>2021-08-13T14:13:51Z</dc:date>
    </item>
  </channel>
</rss>

