All Apps and Add-ons

Is it possible to use only one listener for the Trend Micro Deep Security for Splunk app (by limiting sourcetypes)?

elvintheo
New Member

I know 'Trend Micro Deep Security for Splunk' app by default creates 6 listeners each listening at unique UDP ports. And, this is to classify/separate events based on the source.
Is there a way we can only use one UDP port to listen to events. So, can we use one sourcetype 'deepsecurity' instead of multiple sub sourcetypes like: deepsecurity-antimalware, deepsecurity-web_reputation etc?

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Yes you can. I do it using a syslog server between Splunk and TMDS.

We send syslog from TMDS in cef format to a syslog server and ingest the data into Splunk as sourcetype = deepsecurity:cef

So theoretically you could send the CEF data directly to Splunk and listen on one port with sourcetype=deepsecurity:cef

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Yes you can. I do it using a syslog server between Splunk and TMDS.

We send syslog from TMDS in cef format to a syslog server and ingest the data into Splunk as sourcetype = deepsecurity:cef

So theoretically you could send the CEF data directly to Splunk and listen on one port with sourcetype=deepsecurity:cef

salonyag
New Member

Does the trendmicro app for Splunk work with sourcetype = deepsecurity:cef

0 Karma

jkat54
SplunkTrust
SplunkTrust

Not 100%. Maybe it's just sourcetype=deepsecurity

0 Karma

jkat54
SplunkTrust
SplunkTrust

Check out what's in the TA in props.conf

0 Karma

klaxdal
Contributor

Same here

0 Karma

elvintheo
New Member

This sounds very feasible. Thanks for your answer.

0 Karma
Get Updates on the Splunk Community!

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...

Observability Cloud | AWS PrivateLink Enabled for Splunk Observability Cloud

We’ve enabled AWS PrivateLink for Observability Cloud, giving you an additional inbound connection to send ...

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...