Security & the Enterprise
Much secured. So patch!

Splunk Universal Forwarder vs. E5?

Exodia
Loves-to-Learn

"Bobs Donuts Inc" recently went with CISCO AMP however did not realize this did not have a built-in endpoint firewall.

Currently, their only option right now is to use Windows Firewall/Defender.
At the present moment they are unable to get those logs into their Splunk SIEM.

They have roughly 6000-8000 endpoints in the environment. (Already have an E3 License for each)


For this example, I am looking for pros/cons to going with Universal Forwarder on all endpoints and having those logs sent to the Splunk SIEM vs implementing Microsoft E5 solution.

All suggestions welcome..

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...