Just an announcement post to let people know we have published our TA to the community for Trend Micro Deep Security and ApexOne.
https://splunkbase.splunk.com/app/5349/
This TA falls under our Unified line of TAs and will support as many Trend Micro products as we can.
This TA is actually CIM compliant (vs the usual tick box) and built on large datasets.
Fully compatible with Splunk Enterprise and Splunk Cloud, built by an Ops team for Ops teams.
we tried to implement this TA in our environment at both indexers and HF level, still data is not parsed, we are sending data from TM to syslog-ng server and reading through HF to sent to IDX. we tried using sourcetype=trendmicro and still data is not parsed into other sourcetype. Kindly let me know what i am doing wrong here.