<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trellix/Epo on a windows server sending data to indexers or HF? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639528#M109198</link>
    <description>&lt;P&gt;As far as I remember (but I haven't touched ePO for several years), you just configure it to send syslog to some receiver, right?&lt;/P&gt;&lt;P&gt;Receiving raw network stream by UF of HF is not recommended. You can do that in lab environment but generally the recommended solution is to either use a syslog daemon which will write the events to files and have a forwarder read those files or - recently - use an intermediate "syslog gateway" like SC4S.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 17:07:59 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-04-11T17:07:59Z</dc:date>
    <item>
      <title>How can Trellix/Epo on a windows server send data to indexers or HF?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639430#M109178</link>
      <description>&lt;P&gt;As stated by the Title&lt;/P&gt;
&lt;P&gt;We have a test env for learning but at some point it will be a larger production deployment&lt;/P&gt;
&lt;P&gt;with that said we have a Clustered Env on a vsphere server and one of the boxes is a win2019 server with EPO/Trellix on it.&lt;/P&gt;
&lt;P&gt;So I would really like to know what best practice step by step on sending that data over rom the EPO server to Splunk whether that be to a indexer or to a heavy forwarder?&lt;/P&gt;
&lt;P&gt;Do I need to put up some kind of syslog server somewhere or since its a Windows server should I just put a forwarder on it and use that to send data?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 16:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639430#M109178</guid>
      <dc:creator>domino30</dc:creator>
      <dc:date>2023-04-12T16:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trellix/Epo on a windows server sending data to indexers or HF?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639434#M109179</link>
      <description>&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/5085" target="_blank"&gt;https://splunkbase.splunk.com/app/5085&lt;/A&gt; this is an addon for ePO. See the docs for installation instructions.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 22:40:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639434#M109179</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-04-10T22:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Trellix/Epo on a windows server sending data to indexers or HF?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639514#M109195</link>
      <description>&lt;P&gt;Thanks Pickle Rick&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am aware of the Apps, and I think I know the answer but I want to make sure because there is a lot of documentation about splunk for syslog and what not but I figured since McAfee was on a Windows box I would ask if it would be easier to&amp;nbsp; just put a forwarder on that box and send data to an indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 14:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639514#M109195</guid>
      <dc:creator>domino30</dc:creator>
      <dc:date>2023-04-11T14:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Trellix/Epo on a windows server sending data to indexers or HF?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639528#M109198</link>
      <description>&lt;P&gt;As far as I remember (but I haven't touched ePO for several years), you just configure it to send syslog to some receiver, right?&lt;/P&gt;&lt;P&gt;Receiving raw network stream by UF of HF is not recommended. You can do that in lab environment but generally the recommended solution is to either use a syslog daemon which will write the events to files and have a forwarder read those files or - recently - use an intermediate "syslog gateway" like SC4S.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 17:07:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639528#M109198</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-04-11T17:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Trellix/Epo on a windows server sending data to indexers or HF?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639565#M109205</link>
      <description>&lt;P&gt;Good day -&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Splunk Engineer recommended ePO as the HF&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 21:37:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-Trellix-Epo-on-a-windows-server-send-data-to-indexers-or/m-p/639565#M109205</guid>
      <dc:creator>Doreluss</dc:creator>
      <dc:date>2023-04-11T21:37:55Z</dc:date>
    </item>
  </channel>
</rss>

