- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi I am currently acquiring SEPM logs via syslog and utilizing the old Symantec app . I noticed in the documentation that log dump files are required . Will the app work with syslog output ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


knowledge management is applied to the sourcetype. If the data in your syslog stream is structured the same as in the dump files, then applying the same sourcetype should make it work.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


knowledge management is applied to the sourcetype. If the data in your syslog stream is structured the same as in the dump files, then applying the same sourcetype should make it work.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks ! I will give it a try
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

What sourcetype needs to be applied?
I am sending Symantec logs via syslog to my Splunk server in which one file per day is written to disk and I have Splunk monitoring the directory. The issues I have are 1) How to configure the inputs.conf file (does every line in the stanza simply point to the same directory?), and 2) What sourcetype do I select to ensure Splunk correctly parses out various Symantec log formats from the one log file
Thx,
Jeff
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The structure of the logs is different from those written on disk. Also, anyone know any expedite way to rotate the logs written on disk by SEP?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi @klaxdal
Just to clarify for other users, but are you referring to the Splunk Add-on for Symantec Endpoint Protection? That's what you tagged in your post, but you mentioned using the "old Symantec app". Were you actually referring to the "Splunk for Symantec" app?
https://splunkbase.splunk.com/app/1365/
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Correct - to clarify I am using the old TA's which allow me to retrieve the logs via Syslog . Can I set this up as the same ?
Kris
