Getting Data In

Best way to get Symantec AV data - (reworking an old instance of Splunk)

mhuntington
Explorer

Hello,

I am new to Splunk and was recently given our organization's old Splunk project. Long story, but basically it's been sitting idle for about 6 years.

The first thing I want to do is gather information on our Symantec updates. When Splunk was originally installed consultants used a SQL Server Agent workaround, I guess they couldn't get Symantec to play nice at the time.

I was hoping someone could point me in a good direction for this. What is the best option for this, apps or something else? Is there an app for Symantec?

Tags (1)
0 Karma

ryanoconnor
Builder

I've onboarded Symantec Endpoint Protection logs a number of times and this app is very great:

https://splunkbase.splunk.com/app/2772/

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...