All Apps and Add-ons

Symantec Endpoint Protection to Splunk Cloud

since20982
Engager

Hi,

We are using Splunk Cloud.  

We have installed symantec endpoint protection version 14.3 RU3 build 5413. We are not using symanted endpoint protection manager. We are using symantec cloud hybrid to manage all SEP clients.

Can you please help how can I send symantec endpoint protection client logs from all windows servers to splunk cloud ?  How can I configure data inputs for the same. Sorry I am new to splunk and cannot find any document for symantec endpoint protection to splunk cloud. 

inventsekar
SplunkTrust
SplunkTrust

Hi ..  please check this documentation.. 

https://docs.splunk.com/Documentation/AddOns/released/SymantecEP/About

 

Also with Splunk Cloud, you can reach out to Splunk Cloud Support, they will help you better. 

happy journey with Splunk Cloud!

0 Karma

since20982
Engager

As per my opinon their support is really worst.

This is what Splunk support is saying.

As Support will be handling Break & Fix issues, we don't have any documentation on how to integrate Symantec Endpoint Protection logs with the Splunk Cloud. As informed, kindly reach out to AOD(Admin On Demand) team by contacting your Account Owner.  They will be assisting you with all the required documents and further assistance. Hope you understand the same. Let us know how to proceed further on this case. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...