Security

How to take mcafee virus scan and endpoint security version information into account?

SarahSplunk123
Explorer

Hello,

The EPOProdPropsView_VIRUSCAN fields are not present in the new version of McAfee : Endpoint Security replaces Virus Scan. Therefore, we cannot access the version data anymore, which is a problem for security logs analysis.
We have seen an answer which brings a partial solution to our problem:
https://answers.splunk.com/answers/626506/moving-from-mcafee-vse-to-ens.html
However, the two versions are currently being used, we need the query to take both into account.

Could the Splunk team who develops the McAfee addon update the query to take both versions into account?

Thanks

Best regards,

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...