Splunk Cloud Platform

Integrate Trellix EPO SaaS with Splunk Cloud

phamanh1652
Explorer

I’m trying to forward logs and events from Trellix EPO SaaS to Splunk Cloud for monitoring purposes. To do this, I’ve installed the Trellix EPO SaaS Connector add-on in Splunk. During the setup, the connector requires API credentials to establish communication between Splunk and Trellix. However, even after completing the configuration, I’m not seeing any logs being ingested into Splunk. Additionally, I’m not entirely sure what each field in the configuration tab represents, which makes troubleshooting difficult. So i just configure:
+ IAM URL = Token Endpoint URL in Client Credentials Management
+ API Gateway URL = https://api.manage.trellix.com

I am using Trellix MVISION Trial and Splunk Cloud Trial for testing purpose.

phamanh1652_0-1752737457451.png

phamanh1652_1-1752737479189.png

 

Labels (2)
0 Karma

kiran_panchavat
Champion

@phamanh1652 

Have you created the index called "trellix"? and also check the splunk internal logs on your Splunk Cloud Search head. 

You can use this add-on to integrate your Trellix MVISION. It supports both Splunk Cloud and Splunk Enterprise.

https://splunkbase.splunk.com/app/7022 

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...