I have a question when running the following question in search and reporting for the latest DAT version and AMCORE "
index=* source type=mcafee:epo product="McAfee Endpoint Security", engine version>="6300.9594", dat version>="5051.0" I noticed the out put from Splunk doesn't marry up to the information in McAfee e-Policy. Is there a way to sync both McAfee e-Policy and Splunk , so that way when looking for AMCORE and DAT files they both display the same version.
Is the McAfee Add-on for Splunk configured to show McAfee ENS data ?