Security

How to take mcafee virus scan and endpoint security version information into account?

SarahSplunk123
Explorer

Hello,

The EPOProdPropsView_VIRUSCAN fields are not present in the new version of McAfee : Endpoint Security replaces Virus Scan. Therefore, we cannot access the version data anymore, which is a problem for security logs analysis.
We have seen an answer which brings a partial solution to our problem:
https://answers.splunk.com/answers/626506/moving-from-mcafee-vse-to-ens.html
However, the two versions are currently being used, we need the query to take both into account.

Could the Splunk team who develops the McAfee addon update the query to take both versions into account?

Thanks

Best regards,

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...