"Bobs Donuts Inc" recently went with CISCO AMP however did not realize this did not have a built-in endpoint firewall.
Currently, their only option right now is to use Windows Firewall/Defender.
At the present moment they are unable to get those logs into their Splunk SIEM.
They have roughly 6000-8000 endpoints in the environment. (Already have an E3 License for each)
For this example, I am looking for pros/cons to going with Universal Forwarder on all endpoints and having those logs sent to the Splunk SIEM vs implementing Microsoft E5 solution.
All suggestions welcome..