All Apps and Add-ons

any mcafee network security manager users?

mcbradford
Contributor

We are using McAfee Network Security Manager. We are using the option to send alerts out via syslog. Not all the fields are available, but they are in the mysql db. Has anyone worked on a good sql select to pull most of the alert data per event?

Tags (3)
0 Karma

pedrolito
Explorer

Hello,

I know topic is quiet old, but I currently have the same problem with NSM, so I up this one.

I can't manage to get clear information regarding actions taken by the IPS. I have added variables I need from the McAfee manager, but still can't find the one related to the action.

The Mcafee documentation found [here][1] gives some details, but I would simply modify my props.conf to get actions such as "blocked" and "allowed". And after reading this documentation, I am not able to add an action field for each situation.

FI, I am currently making my McAfee logs IDS CIM Compliant.

Any idea/feedback/rectification would be greatly appreciated !

Thx

0 Karma

tmeader
Contributor

We use the NSM product. You want to directly query the NSM's DB from Splunk as an input? Given our throughput, we'd never be able to do that in a real-time manner (the NSM's are slow enough as it is). Which fields are you looking for that aren't in the log messages (note that you CAN customize the log message format)?

0 Karma

mcbradford
Contributor

Are you on the latest version. I would like to get src/dest country and reputation, plus some of the application identification fields (layer 7 stuff). Past 24 hours 72k events. With proventia 96k past 24 hours and we poll the db for events.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...