Splunk Cloud Platform

Symantec email security.cloud to Splunk Cloud

cnuguri_ncc
Path Finder

Hello,

I am looking to onboard Symantec email security.cloud  data to Splunk cloud, but the add-on seems not compatible/available on Splunk Cloud ( https://splunkbase.splunk.com/app/3830/ ), could someone please advise if there is another way ? 

I suppose using an on-prem HF for the add-on and forward data Splunk could work, although trying to avoid on-prem components if it is possible to onboard directly from IDM.

Thanks in advance.
Chaith

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The standard practice for onboarding data when a TA cannot be installed in Splunk Cloud is to use an on-prem heavy forwarder.

---
If this reply helps you, Karma would be appreciated.

cnuguri_ncc
Path Finder

Thanks @richgalloway 👍

I was hoping to hear that Symantec supports HEC or another way of forwarding logs, before taking the on-prem HF route. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

AFAIK, Symantec does not support HEC, but you could write your own program/script that reads Symantec data and converts it to HEC.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...