Splunk Cloud Platform

Symantec email security.cloud to Splunk Cloud

cnuguri_ncc
Path Finder

Hello,

I am looking to onboard Symantec email security.cloud  data to Splunk cloud, but the add-on seems not compatible/available on Splunk Cloud ( https://splunkbase.splunk.com/app/3830/ ), could someone please advise if there is another way ? 

I suppose using an on-prem HF for the add-on and forward data Splunk could work, although trying to avoid on-prem components if it is possible to onboard directly from IDM.

Thanks in advance.
Chaith

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The standard practice for onboarding data when a TA cannot be installed in Splunk Cloud is to use an on-prem heavy forwarder.

---
If this reply helps you, Karma would be appreciated.

cnuguri_ncc
Path Finder

Thanks @richgalloway 👍

I was hoping to hear that Symantec supports HEC or another way of forwarding logs, before taking the on-prem HF route. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

AFAIK, Symantec does not support HEC, but you could write your own program/script that reads Symantec data and converts it to HEC.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...