- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How should the McAfee Threat Data be ingested into Splunk. Via syslog push or pull by the Mcafee ePO add-on
SamHTexas
Builder
03-22-2021
09:21 AM
I have already installed the Mcafee ePO add-on in Splunk. I am asking about the how data should be ingested into Splunk please? How should the McAfee Threat Data be ingested into Splunk. Via syslog push or pull by the Mcafee ePO add-on? Is the ePO is all that is needed? My Splunk ver is 8.0 .
