Getting Data In

Best way to get Symantec AV data - (reworking an old instance of Splunk)

mhuntington
Explorer

Hello,

I am new to Splunk and was recently given our organization's old Splunk project. Long story, but basically it's been sitting idle for about 6 years.

The first thing I want to do is gather information on our Symantec updates. When Splunk was originally installed consultants used a SQL Server Agent workaround, I guess they couldn't get Symantec to play nice at the time.

I was hoping someone could point me in a good direction for this. What is the best option for this, apps or something else? Is there an app for Symantec?

Tags (1)
0 Karma

ryanoconnor
Builder

I've onboarded Symantec Endpoint Protection logs a number of times and this app is very great:

https://splunkbase.splunk.com/app/2772/

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...