All Apps and Add-ons

Why is the dashboard not showing any data in Splunk Add-on for Symantec Endpoint Protection?

tan_donny
New Member

Hi Folks

I have all my Symantec data collected in an index called Symantec. the data come in from a universal forwarder running on that Symantec log server. I developed and input.conf and prop.conf files, and put them there to make the data in.

Then I install this Splunk Add-on for Symantec Endpoint Protection, hope to have some useful dashboard do a report for me automatically, but nothing shows up. The installation doc does not mention too many details.

Can anybody shed some light on this?

Thank you so much

D

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...