Reporting

How should the McAfee Threat Data be ingested into Splunk. Via syslog push or pull by the Mcafee ePO add-on

SamHTexas
Communicator

I have already installed the Mcafee ePO add-on in Splunk. I am asking about the how data should be ingested into Splunk please? How should the McAfee Threat Data be ingested into Splunk. Via syslog push or pull by the Mcafee ePO add-on? Is the ePO is all that is needed? My Splunk ver is 8.0 .

Labels (1)
0 Karma