<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Symantec End point Protection Dashboard in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508217#M4319</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;This is the dashboard of splunk for symantec.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sc1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9572iFFA84FC7DAFBC378/image-size/large?v=v2&amp;amp;px=999" role="button" title="sc1.PNG" alt="sc1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I checked for "Host with Most Virus Detections in last 24 hours" in main search.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sc2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9574i6F50B12DCFA40E41/image-size/large?v=v2&amp;amp;px=999" role="button" title="sc2.PNG" alt="sc2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What should i do now?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jul 2020 01:59:31 GMT</pubDate>
    <dc:creator>rahul2gupta</dc:creator>
    <dc:date>2020-07-09T01:59:31Z</dc:date>
    <item>
      <title>Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508050#M4313</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We have installed and configured Splunk Add on for symantec endpoint protection&amp;nbsp; successfully.&lt;/P&gt;&lt;P&gt;Splunk has started receiving logs (index=symantec) but we can see nothing on its symantec dashboard as it showing No Results found.&lt;/P&gt;&lt;P&gt;We restarted splunk but it didn't worked.&lt;/P&gt;&lt;P&gt;Please help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 11:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508050#M4313</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-08T11:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508056#M4314</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;check if in the searches there the filter "&lt;SPAN&gt;index=symantec".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If not, Splunk run search on the default indexes and probably sysmantec isn't one of them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You have two solutions:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;insert "index=symantec" in every search (in this case it's better to create an eventtype containing this filter);&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;add symantec to the default indexes for the roles that have to use the dashboards.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;I don't like the second one even if is quicker to implement: I prefer the first because it need more time to implement, but it has more performaces.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 12:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508056#M4314</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-08T12:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508085#M4315</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We have already inserted index="symantec" in inputs.conf.&lt;/P&gt;&lt;P&gt;[monitor://%SEPM_HOME%\data\dump\scm_admin.tmp]&lt;BR /&gt;sourcetype = symantec:ep:admin:file&lt;BR /&gt;index=symantec&lt;BR /&gt;disabled = false&lt;/P&gt;&lt;P&gt;[monitor://%SEPM_HOME%\data\dump\agt_behavior.tmp]&lt;BR /&gt;sourcetype = symantec:ep:behavior:file&lt;BR /&gt;index=symantec&lt;BR /&gt;disabled = false&lt;/P&gt;&lt;P&gt;[monitor://%SEPM_HOME%\data\dump\scm_agent_act.tmp]&lt;BR /&gt;sourcetype = symantec:ep:agent:file&lt;BR /&gt;index=symantec&lt;BR /&gt;disabled = false&lt;/P&gt;&lt;P&gt;[monitor://%SEPM_HOME%\data\dump\scm_policy.tmp]&lt;BR /&gt;sourcetype = symantec:ep:policy:file&lt;BR /&gt;index=symantec&lt;BR /&gt;disabled = false&lt;/P&gt;&lt;P&gt;But although we are getting nothing on dashboard.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 13:24:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508085#M4315</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-08T13:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508087#M4316</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you run a simple search&amp;nbsp;&lt;SPAN&gt;index="symantec", what are the results?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you have events, the problem is in the dashboard, and I think that's the one I described below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I you haven't events there's a problem in input.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What's your situation?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Only one additional heck: are the users using the dashboard administrators? if not, check if thei role has the grants on the symantec index.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 13:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508087#M4316</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-08T13:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508095#M4317</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;When we run the query index="symantec",we get the following output.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sya.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9567i1DE2265FAA8791D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="sya.PNG" alt="sya.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Only one additional heck: are the users using the dashboard administrators? if not, check if there role has the grants on the symantec index. -- How to check this?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 13:49:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508095#M4317</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-08T13:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508118#M4318</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;running a search and having results means that your user has the grants to access the index, but you probably are an administrator, maybe the users has different roles, so check in [Settings -- Roles] if the roles associated to the users that are using the dashboard has access to the index.&lt;/P&gt;&lt;P&gt;Anyway, the presence of logs in index=symantec means that input is correct, now, you have to check why data aren't displayed in dashboard.&lt;/P&gt;&lt;P&gt;You can open in search one of dashboard panels clicking on the&amp;nbsp;magnifying glass (bottom right).&lt;/P&gt;&lt;P&gt;Then you can check if in the main search there is or not "index=symantec" so it's possible to understand where's the problem.&lt;/P&gt;&lt;P&gt;If you want help, share one of these searches.&lt;/P&gt;&lt;P&gt;To avoid path problems, go in [Settings -- Roles -- &amp;lt;your_role&amp;gt; -- Indexes] and flag the symantec index in both the columns (Included and Default).&lt;/P&gt;&lt;P&gt;In few words, if you don't explain in your search the index to search, Splunk searches on all the indexes in the default path, for this reason I always prefer to insert index in the main search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 14:51:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508118#M4318</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-08T14:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508217#M4319</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;This is the dashboard of splunk for symantec.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sc1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9572iFFA84FC7DAFBC378/image-size/large?v=v2&amp;amp;px=999" role="button" title="sc1.PNG" alt="sc1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I checked for "Host with Most Virus Detections in last 24 hours" in main search.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sc2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9574i6F50B12DCFA40E41/image-size/large?v=v2&amp;amp;px=999" role="button" title="sc2.PNG" alt="sc2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What should i do now?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 01:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508217#M4319</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-09T01:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508241#M4320</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;dashboard panel is populated using a macro, so you have to go in [Settings -- Advanced Search -- Search Macros] and open in edit the macro contained in your panel (in your screenshot "host_overview_most_viruses_last_24hours"), viewing if there's the index in the main search.&lt;/P&gt;&lt;P&gt;If not (I think so) add it and save the macro.&lt;/P&gt;&lt;P&gt;Otherwise you can add the symantec index to the default path as I described in a previous answer.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 06:41:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508241#M4320</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-09T06:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508250#M4322</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Following is the search.&lt;/P&gt;&lt;P&gt;`sep_index` `sep_risk_sourcetype` action=allowed OR action=deferred AND risk_type="Virus found" | rename actual_action as "Action" dest_nt_host as "Host" dest_ip as "Host IP" user as "User" risk_type as "Detection Type" signature as "Malware Name" | stats count by Host "Host IP" User | sort -count&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sc3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9580i42919E5774446220/image-size/large?v=v2&amp;amp;px=999" role="button" title="sc3.PNG" alt="sc3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What modifications do I need to do.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 07:49:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508250#M4322</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-09T07:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508251#M4323</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as you can see, you have a macro inside another macro, so you have to open the&amp;nbsp;&lt;SPAN&gt;sep_index macro and see what's containing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the symantec index isn't present, you have to insert in it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 08:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508251#M4323</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-09T08:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508291#M4325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you very much for your continuous support.This problem is resolved.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 12:40:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508291#M4325</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-09T12:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec End point Protection Dashboard</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508293#M4326</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good! you're welcome.&lt;/P&gt;&lt;P&gt;Ciao and see next time!&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are valued.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 12:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Symantec-End-point-Protection-Dashboard/m-p/508293#M4326</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-09T12:45:06Z</dc:date>
    </item>
  </channel>
</rss>

