All Apps and Add-ons
Highlighted

How can we send Symantec DLP incidents from DLP to Splunk?

New Member

Hi,

I am fairly new to Splunk but have worked on Symantec DLP.

I would like to know how can we send DLP Incidents from DLP to Splunk.

0 Karma
Highlighted

Re: How can we send Symantec DLP incidents from DLP to Splunk?

SplunkTrust
SplunkTrust

There's an app for that. https://splunkbase.splunk.com/app/3029/

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How can we send Symantec DLP incidents from DLP to Splunk?

New Member

Yes, I have installed the app in Splunk web.

However, I am not sure how I configure DLP side to send incidents to this app. I have configured TCP input on Splunk too (Port 514) and a response rule in DLP with following details :
Host:

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.