All Apps and Add-ons

How can we send Symantec DLP incidents from DLP to Splunk?

New Member

Hi,

I am fairly new to Splunk but have worked on Symantec DLP.

I would like to know how can we send DLP Incidents from DLP to Splunk.

0 Karma
Highlighted

Re: How can we send Symantec DLP incidents from DLP to Splunk?

SplunkTrust
SplunkTrust

There's an app for that. https://splunkbase.splunk.com/app/3029/

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How can we send Symantec DLP incidents from DLP to Splunk?

New Member

Yes, I have installed the app in Splunk web.

However, I am not sure how I configure DLP side to send incidents to this app. I have configured TCP input on Splunk too (Port 514) and a response rule in DLP with following details :
Host:

0 Karma