Splunk Cloud Platform

Symantec email security.cloud to Splunk Cloud

cnuguri_ncc
Path Finder

Hello,

I am looking to onboard Symantec email security.cloud  data to Splunk cloud, but the add-on seems not compatible/available on Splunk Cloud ( https://splunkbase.splunk.com/app/3830/ ), could someone please advise if there is another way ? 

I suppose using an on-prem HF for the add-on and forward data Splunk could work, although trying to avoid on-prem components if it is possible to onboard directly from IDM.

Thanks in advance.
Chaith

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The standard practice for onboarding data when a TA cannot be installed in Splunk Cloud is to use an on-prem heavy forwarder.

---
If this reply helps you, Karma would be appreciated.

cnuguri_ncc
Path Finder

Thanks @richgalloway 👍

I was hoping to hear that Symantec supports HEC or another way of forwarding logs, before taking the on-prem HF route. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

AFAIK, Symantec does not support HEC, but you could write your own program/script that reads Symantec data and converts it to HEC.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...