I have been unsuccessful in getting Microsoft System Center 2012 Endpoint Protection events into Splunk ES. The Endpoint Protection deployment is currently reporting in SCCM without an issue, as alerts have been configured correctly in SCCM.
The SCCM servers have the Universal Forwarder installed and has the following configuration in inputs.conf to monitor the SCCM logs:
I have restarted the service for the Universal forwarder on the SCCM servers and have verified that I am in fact receivng logs from the servers, however I am not receiving any Endpoint Protection events.
Am I missing something? Thanks in advance!
Splunk version: 6.1
Splunk ES version: 3.0
Universal forwarder version on SCCM servers: 5.0.2