<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: McAfee epo integration with Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96310#M20091</link>
    <description>&lt;P&gt;Hi Aaron, according to &lt;A href="http://kc.mcafee.com/corporate/index?page=answerlink&amp;amp;url=spD2Ro8-7xeSDi5pMVrcP4NU4ttaDgfvDk2wLTCzMyuMz4oyiLGtCwXyK-df8-rTJFeDr-E2d5KAfwI6LVw1bnWuIQsNjHpp38oNnKthbAH6Wc3uAV-hNpjW3UWjKYYsGpZI9jjhwVKI1eUpoOcSUeU-qClOYC9FdHJAIZeHvnV1D7BddyGF4Wl3Dbj!5NFlu1RIhjiLdQqM2H2GOdxPHEZ0vPcJgGQP&amp;amp;answerid=16777216&amp;amp;searchid=1378124191887"&gt;http://kc.mcafee.com/corporate/index?page=answerlink&amp;amp;url=spD2Ro8-7xeSDi5pMVrcP4NU4ttaDgfvDk2wLTCzMyuMz4oyiLGtCwXyK-df8-rTJFeDr-E2d5KAfwI6LVw1bnWuIQsNjHpp38oNnKthbAH6Wc3uAV-hNpjW3UWjKYYsGpZI9jjhwVKI1eUpoOcSUeU-qClOYC9FdHJAIZeHvnV1D7BddyGF4Wl3Dbj!5NFlu1RIhjiLdQqM2H2GOdxPHEZ0vPcJgGQP&amp;amp;answerid=16777216&amp;amp;searchid=1378124191887&lt;/A&gt; you can configure the logs in a matter so it will write a txt log file. This can be monitored by Splunk, read more here &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Sep 2013 12:20:58 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2013-09-02T12:20:58Z</dc:date>
    <item>
      <title>McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96303#M20084</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;We have to integrate McAfee epo(full fledged) instance with splunk i.e we want logs of EPO in splunk. What is the best way to do it. Should i install Universal forwarder on the epo machine or should i use EPO extended configuration and register my splunk as a syslog server there(donot know how to do this).Also we donot want to use ESS for this. Please help !!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2013 06:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96303#M20084</guid>
      <dc:creator>lohit</dc:creator>
      <dc:date>2013-07-16T06:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96304#M20085</link>
      <description>&lt;P&gt;Hi lohit,&lt;/P&gt;

&lt;P&gt;both will work fine, if you can configure and/or setup it up in EPO. &lt;BR /&gt;
&lt;CODE&gt;Syslog&lt;/CODE&gt; has some down sides, like data can get lost if the indexer is down for example. Personally I would configure EPO to create text Log file and install a Splunk Universalforwarder to monitor the log. &lt;/P&gt;

&lt;P&gt;Hope this helps a bit to get you started.&lt;/P&gt;

&lt;P&gt;Cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2013 06:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96304#M20085</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-07-16T06:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96305#M20086</link>
      <description>&lt;P&gt;Thanks a lot MuS.&lt;/P&gt;

&lt;P&gt;Totally agree with syslog downside. Only positive points from EPO setup is that we can actually log only a specific type of events to a syslog server from EPO console like for example based on severity instead of collecting all logs and then extracting it in splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2013 06:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96305#M20086</guid>
      <dc:creator>lohit</dc:creator>
      <dc:date>2013-07-16T06:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96306#M20087</link>
      <description>&lt;P&gt;Were you able to do this? If so please share a little how to.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2013 21:47:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96306#M20087</guid>
      <dc:creator>adrianathome</dc:creator>
      <dc:date>2013-08-27T21:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96307#M20088</link>
      <description>&lt;P&gt;Which part are you having trouble with?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2013 21:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96307#M20088</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-27T21:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96308#M20089</link>
      <description>&lt;P&gt;Interested in a procedure to have epo write logs to text file. Also any props/transforms for the epo data.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2013 03:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96308#M20089</guid>
      <dc:creator>adrianathome</dc:creator>
      <dc:date>2013-08-29T03:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96309#M20090</link>
      <description>&lt;P&gt;Can anyone provide any further info on how to get EPO to export to a .txt file and then monitor with Splunk ?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2013 11:54:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96309#M20090</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2013-09-02T11:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96310#M20091</link>
      <description>&lt;P&gt;Hi Aaron, according to &lt;A href="http://kc.mcafee.com/corporate/index?page=answerlink&amp;amp;url=spD2Ro8-7xeSDi5pMVrcP4NU4ttaDgfvDk2wLTCzMyuMz4oyiLGtCwXyK-df8-rTJFeDr-E2d5KAfwI6LVw1bnWuIQsNjHpp38oNnKthbAH6Wc3uAV-hNpjW3UWjKYYsGpZI9jjhwVKI1eUpoOcSUeU-qClOYC9FdHJAIZeHvnV1D7BddyGF4Wl3Dbj!5NFlu1RIhjiLdQqM2H2GOdxPHEZ0vPcJgGQP&amp;amp;answerid=16777216&amp;amp;searchid=1378124191887"&gt;http://kc.mcafee.com/corporate/index?page=answerlink&amp;amp;url=spD2Ro8-7xeSDi5pMVrcP4NU4ttaDgfvDk2wLTCzMyuMz4oyiLGtCwXyK-df8-rTJFeDr-E2d5KAfwI6LVw1bnWuIQsNjHpp38oNnKthbAH6Wc3uAV-hNpjW3UWjKYYsGpZI9jjhwVKI1eUpoOcSUeU-qClOYC9FdHJAIZeHvnV1D7BddyGF4Wl3Dbj!5NFlu1RIhjiLdQqM2H2GOdxPHEZ0vPcJgGQP&amp;amp;answerid=16777216&amp;amp;searchid=1378124191887&lt;/A&gt; you can configure the logs in a matter so it will write a txt log file. This can be monitored by Splunk, read more here &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2013 12:20:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96310#M20091</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-09-02T12:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: McAfee epo integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96311#M20092</link>
      <description>&lt;P&gt;FYI, there's now a DB Connect based way to do EPO logs too: &lt;A href="http://apps.splunk.com/app/1819/"&gt;http://apps.splunk.com/app/1819/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2014 18:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/McAfee-epo-integration-with-Splunk/m-p/96311#M20092</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2014-07-08T18:56:53Z</dc:date>
    </item>
  </channel>
</rss>

