<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SCCM 2012 Endpoint Protection Reporting in Splunk ES in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SCCM-2012-Endpoint-Protection-Reporting-in-Splunk-ES/m-p/195123#M988</link>
    <description>&lt;P&gt;hi, that will need some add-on work to model the data (field extractions and tags). Here's the endpoint model: &lt;A href="http://docs.splunk.com/Documentation/CIM/latest/User/Malware"&gt;http://docs.splunk.com/Documentation/CIM/latest/User/Malware&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here's some TA-building advice: &lt;A href="http://blogs.splunk.com/2014/01/01/building-technology-add-ons/"&gt;http://blogs.splunk.com/2014/01/01/building-technology-add-ons/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jun 2014 20:59:22 GMT</pubDate>
    <dc:creator>jcoates_splunk</dc:creator>
    <dc:date>2014-06-10T20:59:22Z</dc:date>
    <item>
      <title>SCCM 2012 Endpoint Protection Reporting in Splunk ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SCCM-2012-Endpoint-Protection-Reporting-in-Splunk-ES/m-p/195122#M987</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I have been unsuccessful in getting Microsoft System Center 2012 Endpoint Protection events into Splunk ES.  The Endpoint Protection deployment is currently reporting in SCCM without an issue, as alerts have been configured correctly in SCCM.&lt;/P&gt;

&lt;P&gt;The SCCM servers have the Universal Forwarder installed and has the following configuration in inputs.conf to monitor the SCCM logs:&lt;/P&gt;

&lt;P&gt;[monitor://D:\Program Files\Microsoft Configuration Manager\Logs*.log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
current_only=0&lt;/P&gt;

&lt;P&gt;I have restarted the service for the Universal forwarder on the SCCM servers and have verified that I am in fact receivng  logs from the servers, however I am not receiving any Endpoint Protection events.  &lt;/P&gt;

&lt;P&gt;Am I missing something?  Thanks in advance!&lt;/P&gt;

&lt;P&gt;Splunk version: 6.1&lt;BR /&gt;
Splunk ES version: 3.0&lt;BR /&gt;
Universal forwarder version on SCCM servers: 5.0.2&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 20:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SCCM-2012-Endpoint-Protection-Reporting-in-Splunk-ES/m-p/195122#M987</guid>
      <dc:creator>dxmiller</dc:creator>
      <dc:date>2014-06-10T20:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM 2012 Endpoint Protection Reporting in Splunk ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SCCM-2012-Endpoint-Protection-Reporting-in-Splunk-ES/m-p/195123#M988</link>
      <description>&lt;P&gt;hi, that will need some add-on work to model the data (field extractions and tags). Here's the endpoint model: &lt;A href="http://docs.splunk.com/Documentation/CIM/latest/User/Malware"&gt;http://docs.splunk.com/Documentation/CIM/latest/User/Malware&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here's some TA-building advice: &lt;A href="http://blogs.splunk.com/2014/01/01/building-technology-add-ons/"&gt;http://blogs.splunk.com/2014/01/01/building-technology-add-ons/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 20:59:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SCCM-2012-Endpoint-Protection-Reporting-in-Splunk-ES/m-p/195123#M988</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2014-06-10T20:59:22Z</dc:date>
    </item>
  </channel>
</rss>

