Getting Data In

How do you get logs from Mcafee IPS into Splunk?

riqbal
Communicator

I have McAfee IPS. How do I integrate or Collect logs from Mcafee IPS and forward the logs to Splunk?

Currently, I am forwarding logs directly to Splunk on UDP port.

Tags (1)
0 Karma

FrankVl
Ultra Champion

http://docs.splunk.com/Documentation/AddOns/released/McAfeeEPO/ConfigureSyslogInput

"Configure Network Security Platform (Intrushield) to send syslog to a Splunk Enterprise receiving network port or a syslog server that writes to a directory that Splunk Enterprise monitors."

The latter method (using a syslog server, rather than direct network input to splunk) is generally the recommended approach for any syslog source.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...