All Apps and Add-ons

McAfee ePo and Splunk "McAfee Add-on

Doreluss
Loves-to-Learn Lots

I have a question when running the following question in search and reporting for the latest DAT version and AMCORE  "
index=* source type=mcafee:epo product="McAfee Endpoint Security", engine version>="6300.9594", dat version>="5051.0"  I noticed the out put from Splunk doesn't marry up to the information in McAfee e-Policy. Is there a way to  sync both McAfee e-Policy and Splunk , so that way when looking for AMCORE and DAT files they both display the same version.

Is the McAfee Add-on for Splunk configured to show McAfee ENS data ?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...