<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to pull logs from Symantec Protection Engine? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412151#M6534</link>
    <description>&lt;P&gt;QRadar has the ability to gather logs from sources (like SPE). I believe its using API. Is there something similar for Splunk? &lt;/P&gt;</description>
    <pubDate>Tue, 27 Nov 2018 07:43:52 GMT</pubDate>
    <dc:creator>vrattlesnake</dc:creator>
    <dc:date>2018-11-27T07:43:52Z</dc:date>
    <item>
      <title>How to pull logs from Symantec Protection Engine?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412149#M6532</link>
      <description>&lt;P&gt;Can we pull the logs from Splunk end instead of sending them from Symantec Protection Engine  using a third party tool? I know it is possible using QRadar, not sure how it works on Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 05:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412149#M6532</guid>
      <dc:creator>vrattlesnake</dc:creator>
      <dc:date>2018-11-27T05:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs from Symantec Protection Engine?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412150#M6533</link>
      <description>&lt;P&gt;&lt;EM&gt;Can we pull the logs from Splunk end instead of sending them from Symantec Protection Engine using a third party tool?&lt;/EM&gt;&lt;BR /&gt;
Not sure of this above sentence. &lt;/P&gt;

&lt;P&gt;Please update us - you would like to send data&lt;BR /&gt;
from Symantec Protection Engine to Splunk? &lt;BR /&gt;
or &lt;BR /&gt;
from Splunk to Symantec Protection Engine?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 07:24:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412150#M6533</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-11-27T07:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs from Symantec Protection Engine?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412151#M6534</link>
      <description>&lt;P&gt;QRadar has the ability to gather logs from sources (like SPE). I believe its using API. Is there something similar for Splunk? &lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 07:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412151#M6534</guid>
      <dc:creator>vrattlesnake</dc:creator>
      <dc:date>2018-11-27T07:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs from Symantec Protection Engine?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412152#M6535</link>
      <description>&lt;P&gt;QRadar has the ability to gather logs from sources (like SPE)/// &lt;BR /&gt;
Yes, Splunk has the same ability.&lt;/P&gt;

&lt;P&gt;You can install a splunk universal forwarder on a host and configure it to collect logs. most of the famous appliances/applications are having their own custom built "splunk apps", which will do most of the collection and configuration tasks. &lt;/P&gt;

&lt;P&gt;Please check these - &lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2772/"&gt;https://splunkbase.splunk.com/app/2772/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.symantec.com/connect/groups/symantec-apps-splunk"&gt;https://www.symantec.com/connect/groups/symantec-apps-splunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;As you are a new user to Splunk Answers, you can upvote the answers/comments, &lt;BR /&gt;
if this answer resolved your query, you can select this answer and "accept" it as the answer, so that this question will be moved to answered queue. Happy Splunking!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 08:30:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412152#M6535</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-11-27T08:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs from Symantec Protection Engine?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412153#M6536</link>
      <description>&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2772/"&gt;https://splunkbase.splunk.com/app/2772/&lt;/A&gt;&lt;BR /&gt;
this is for SEP not SPE. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.symantec.com/connect/groups/symantec-apps-splunk"&gt;https://www.symantec.com/connect/groups/symantec-apps-splunk&lt;/A&gt;&lt;BR /&gt;
I dont see SPE in this. So i guess Splunk forwarder is how i should proceed. I will look into it. Thanks. &lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 10:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412153#M6536</guid>
      <dc:creator>vrattlesnake</dc:creator>
      <dc:date>2018-11-27T10:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs from Symantec Protection Engine?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412154#M6537</link>
      <description>&lt;P&gt;yep, if you can install a splunk universal forwarder(UF), you can do all pull all kinds of logs. &lt;BR /&gt;
(i didnt know Symantec Protection Engine, otherwise, i should have suggested Splunk UF at first itself).&lt;BR /&gt;
maybe, please accept this as the answer, so that this question will be moved from unanswered to answered. thanks. &lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 10:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412154#M6537</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-11-27T10:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs from Symantec Protection Engine?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412155#M6538</link>
      <description>&lt;P&gt;Thank you. &lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 08:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-pull-logs-from-Symantec-Protection-Engine/m-p/412155#M6538</guid>
      <dc:creator>vrattlesnake</dc:creator>
      <dc:date>2018-12-04T08:11:51Z</dc:date>
    </item>
  </channel>
</rss>

