<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Symantec Endpoint Reporting App (SEP) Installation in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82628#M20979</link>
    <description>&lt;P&gt;Updated the documentation - thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2011 16:09:52 GMT</pubDate>
    <dc:creator>Brian_Osburn</dc:creator>
    <dc:date>2011-08-04T16:09:52Z</dc:date>
    <item>
      <title>Symantec Endpoint Reporting App (SEP) Installation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82626#M20977</link>
      <description>&lt;P&gt;Hello, I'm new to Splunk and I'm having some difficulty getting the SEP app working correctly.&lt;/P&gt;

&lt;P&gt;(replace the dashes below with underscores..)&lt;/P&gt;

&lt;P&gt;I do not see any data when I go to App -&amp;gt; Symantec Endpoint Protection Reporting, although I know that SEP logs are being indexed in prod-sep-logs because I can go to the search app and search for index="prod-sep-logs" and get results&lt;/P&gt;

&lt;P&gt;Back on the SEP app, under 'Top Infections By Type,' if I click More Info (beside No Results Found) I see the following.. This search has completed and found 12,205 matching events. However, the transforming commands in the highlighted portion of the following search: search eventtype="sep-virusfound"  | top  limit=50 sep-riskname (top limit=50 sep-riskname is the part that is highlighted)&lt;/P&gt;

&lt;P&gt;Back on the Search app ,if i search index="prod-sep-logs" I see that my logs currently contain 10 eventtypes including sep-virusfound, sep-management-downloadcontent, sep-management-receivelog, and so on.. so it appears that the eventtypes are working correctly&lt;/P&gt;

&lt;P&gt;On the Search app, if I search - index="prod-sep-logs" eventtype="sep-virusfound" - I see all of the logs for this eventtype, but I do not see under 'Selected fields' or 'Other interesting fields' entries for sep-computername or sep-riskname, and if I append - | top sep-computername - or - | top sep-riskname - to my search I receive no results. So from my limited experience it looks like maybe the field extractions are not working correctly.&lt;/P&gt;

&lt;P&gt;So I went to Manager and the Field Transformations and grabbed the regular expression for sep-virusfound.. I went to the Search app and searched for - index="prod-sep-logs" eventtype="sep-virusfound" -, then I selected Extract fields and under Generated pattern i clicked Edit and pasted the regex for sep-virusfound and clicked Apply..  Under Sample Extractions it appears to pull data correctly for sep-actualaction, sep-computername, sep-domainname, sep-endtime, ..., sep-username.. so the regex appears to be working correctly&lt;/P&gt;

&lt;P&gt;Any idea why the regex is working correctly, but Splunk does not appear to know about the Fields?&lt;/P&gt;

&lt;P&gt;Thanks for any help you can provide&lt;/P&gt;

&lt;P&gt;Heath&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2011 14:31:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82626#M20977</guid>
      <dc:creator>hcorbett_</dc:creator>
      <dc:date>2011-04-15T14:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec Endpoint Reporting App (SEP) Installation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82627#M20978</link>
      <description>&lt;P&gt;We just had the same problem.  Check props.conf for the app.  The delivered sourcetype "prod_sep_logs" did not match the sourcetype for our SEP logs.  Once we matched them up it started working as expected.&lt;/P&gt;

&lt;P&gt;Cheers, Dave&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:46:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82627#M20978</guid>
      <dc:creator>dmceccoli</dc:creator>
      <dc:date>2020-09-28T09:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec Endpoint Reporting App (SEP) Installation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82628#M20979</link>
      <description>&lt;P&gt;Updated the documentation - thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2011 16:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82628#M20979</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-08-04T16:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec Endpoint Reporting App (SEP) Installation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82629#M20980</link>
      <description>&lt;P&gt;copying props.conf to 'local' and editing the [prod_sep_log] to match the inputs.conf sourcetype and restarting splunk didnt fix it. Whats wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82629#M20980</guid>
      <dc:creator>BP9906</dc:creator>
      <dc:date>2020-09-28T12:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec Endpoint Reporting App (SEP) Installation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82630#M20981</link>
      <description>&lt;P&gt;Discovered the SEP12 syslog is different than SEP11. I'm going to suggest a transformation change to support either.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 16:14:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Symantec-Endpoint-Reporting-App-SEP-Installation/m-p/82630#M20981</guid>
      <dc:creator>BP9906</dc:creator>
      <dc:date>2012-09-17T16:14:32Z</dc:date>
    </item>
  </channel>
</rss>

