All Apps and Add-ons

any mcafee network security manager users?

mcbradford
Contributor

We are using McAfee Network Security Manager. We are using the option to send alerts out via syslog. Not all the fields are available, but they are in the mysql db. Has anyone worked on a good sql select to pull most of the alert data per event?

Tags (3)
0 Karma

pedrolito
Explorer

Hello,

I know topic is quiet old, but I currently have the same problem with NSM, so I up this one.

I can't manage to get clear information regarding actions taken by the IPS. I have added variables I need from the McAfee manager, but still can't find the one related to the action.

The Mcafee documentation found [here][1] gives some details, but I would simply modify my props.conf to get actions such as "blocked" and "allowed". And after reading this documentation, I am not able to add an action field for each situation.

FI, I am currently making my McAfee logs IDS CIM Compliant.

Any idea/feedback/rectification would be greatly appreciated !

Thx

0 Karma

tmeader
Contributor

We use the NSM product. You want to directly query the NSM's DB from Splunk as an input? Given our throughput, we'd never be able to do that in a real-time manner (the NSM's are slow enough as it is). Which fields are you looking for that aren't in the log messages (note that you CAN customize the log message format)?

0 Karma

mcbradford
Contributor

Are you on the latest version. I would like to get src/dest country and reputation, plus some of the application identification fields (layer 7 stuff). Past 24 hours 72k events. With proventia 96k past 24 hours and we poll the db for events.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...