Hello,
we are just starting the integration of SEP via Syslog, and notice that this TA seems not to work with all (new) Sourcetypes / Fields.
There is another "official" Version of the App, which requires a file based forwarding to Splunk (we prefere syslog!).
Is anybody successfully using this TA with latest SEP Version?
Kind regards