Getting Data In

What type of data in addition to sysloag should be ingested into Splunk to help SOC team? I already have the ePO add on

SamHTexas
Builder

What type of data in addition to sysloag should be ingested into Splunk to help SOC team? I already have the ePO add on installed. Do I need additional apps or TAs?

Tags (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @SamHTexas 

As per the installation instructions the add-on could have been installed on SH ( for knowledge management), HF / Indexer/ UF depends on your environment ( to ingest the syslogs).  Install the Splunk Add-on for McAfee ePO Syslog - Splunk Documentation

Add-on sourcetype supports these CIM compatible Intrusion Detection,
Malware datamodels  according to Splunk docs - Source types for the Splunk Add-on for McAfee ePO Syslog - Splunk Documentation.  Hence if the add-on correctly installed on SH, and syslog data is getting ingested then that is all SOC team wanted for their usecases.

---------------------------------------------

An upvote would be appreciated if it helps!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...