<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Queries Template for McAfee ePO in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502267#M139809</link>
    <description>&lt;P&gt;Well, unless you want to ingest something very specific from a table, from ePO's database, I'd suggest to go with this. Easy integration, and will get you all the required threat logs into Splunk in a hassle free manner.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://splunkbase.splunk.com/app/1819/#/details" target="test_blank"&gt;https://splunkbase.splunk.com/app/1819/#/details&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 22 May 2020 21:39:49 GMT</pubDate>
    <dc:creator>shivanshu1593</dc:creator>
    <dc:date>2020-05-22T21:39:49Z</dc:date>
    <item>
      <title>Queries Template for McAfee ePO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502263#M139805</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;

&lt;P&gt;We just integrate Splunk with McAfee ePO via DB Connect.&lt;/P&gt;

&lt;P&gt;We're trying to get some informations from ePO, but, the default queries on it is just about antivirus.&lt;/P&gt;

&lt;P&gt;Is there any query template that I can use to get informations from ePO?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 14:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502263#M139805</guid>
      <dc:creator>raphaalmeida</dc:creator>
      <dc:date>2020-05-22T14:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Queries Template for McAfee ePO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502264#M139806</link>
      <description>&lt;P&gt;Hello @raphaalmeida &lt;/P&gt;

&lt;P&gt;default query get all relevant fields, which are populated by other components, not just antivirus. Are other events present in the DB already? Which events are stored in the DB  can be configured on the ePO &amp;gt; Configuration &amp;gt; Server Settings &amp;gt; Event Filtering under Setting Categories and click Edit.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 16:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502264#M139806</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-05-22T16:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Queries Template for McAfee ePO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502265#M139807</link>
      <description>&lt;P&gt;Hello @PavelP &lt;/P&gt;

&lt;P&gt;Thanks for your response.&lt;/P&gt;

&lt;P&gt;There some events selected on that tab you mentioned, also, I've selected to store both on ePO and SIEM (this SIEM is McAfee SIEM or any SIEM?).&lt;/P&gt;

&lt;P&gt;For Splunk, I'm doing this: In ePO, I'm going under query&amp;amp;reports &amp;gt; selecting a query checkbox &amp;gt; Actions button &amp;gt; View SQL.&lt;/P&gt;

&lt;P&gt;I'm sending that SQL query to Splunk. Is this correct?&lt;/P&gt;

&lt;P&gt;thanks for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 16:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502265#M139807</guid>
      <dc:creator>raphaalmeida</dc:creator>
      <dc:date>2020-05-22T16:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Queries Template for McAfee ePO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502266#M139808</link>
      <description>&lt;P&gt;@raphaalmeida&lt;/P&gt;

&lt;P&gt;store in ePO - store in the SQL DB&lt;/P&gt;

&lt;P&gt;store in SIEM - send to SIEM via syslog over TLS&lt;/P&gt;

&lt;P&gt;The SQL expression you got via query&amp;amp;reports is a ePO way to build an ePO report, I'm not sure you are on the right track this way.&lt;/P&gt;

&lt;P&gt;You can start with following the documentation step by step: &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/McAfeeEPO/ConfigureDBConnectv3inputs"&gt;https://docs.splunk.com/Documentation/AddOns/released/McAfeeEPO/ConfigureDBConnectv3inputs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and tune it later when you get if work.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 21:28:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502266#M139808</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-05-22T21:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Queries Template for McAfee ePO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502267#M139809</link>
      <description>&lt;P&gt;Well, unless you want to ingest something very specific from a table, from ePO's database, I'd suggest to go with this. Easy integration, and will get you all the required threat logs into Splunk in a hassle free manner.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://splunkbase.splunk.com/app/1819/#/details" target="test_blank"&gt;https://splunkbase.splunk.com/app/1819/#/details&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 22 May 2020 21:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502267#M139809</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2020-05-22T21:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Queries Template for McAfee ePO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502268#M139810</link>
      <description>&lt;P&gt;Hello @shivanshu1593 &lt;/P&gt;

&lt;P&gt;Our Splunk Analyst already installed DB connect.&lt;/P&gt;

&lt;P&gt;I'm trying to figure if, McAfee needs to provide the queries for us or our Splunk Analyst needs to know what he wants and know the queries.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 12:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502268#M139810</guid>
      <dc:creator>raphaalmeida</dc:creator>
      <dc:date>2020-05-26T12:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Queries Template for McAfee ePO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502269#M139811</link>
      <description>&lt;P&gt;Hey @PavelP &lt;/P&gt;

&lt;P&gt;Thanks for your explanation. I'm really new to this and still understanding how everything works.&lt;/P&gt;

&lt;P&gt;I'll tell to our Splunk analyst to try to follow that document and keep you in touch.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 12:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-Template-for-McAfee-ePO/m-p/502269#M139811</guid>
      <dc:creator>raphaalmeida</dc:creator>
      <dc:date>2020-05-26T12:18:50Z</dc:date>
    </item>
  </channel>
</rss>

