I’m trying to forward logs and events from Trellix EPO SaaS to Splunk Cloud for monitoring purposes. To do this, I’ve installed the Trellix EPO SaaS Connector add-on in Splunk. During the setup, the connector requires API credentials to establish communication between Splunk and Trellix. However, even after completing the configuration, I’m not seeing any logs being ingested into Splunk. Additionally, I’m not entirely sure what each field in the configuration tab represents, which makes troubleshooting difficult. So i just configure:
+ IAM URL = Token Endpoint URL in Client Credentials Management
+ API Gateway URL = https://api.manage.trellix.com
I am using Trellix MVISION Trial and Splunk Cloud Trial for testing purpose.
Have you created the index called "trellix"? and also check the splunk internal logs on your Splunk Cloud Search head.
You can use this add-on to integrate your Trellix MVISION. It supports both Splunk Cloud and Splunk Enterprise.
https://splunkbase.splunk.com/app/7022