Splunk Enterprise

How to push symantec antivirus integration with splunk

human96
Communicator

[ VERY URGENT ]

 

Hi all, Does anyone has knowledge about how to push symantec antivirus logs to splunk or pull logs from symantec antivirus. 

step - by - step process to do it.

 

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

There add on for Symantec Endpoint Protection https://splunkbase.splunk.com/app/2772/#/overview 
can you please check if this helps your requirement 

also splunk doc for https://docs.splunk.com/Documentation/AddOns/released/SymantecEP/About  for detailed  steps 

human96
Communicator

hi @SanjayReddy , thank you so much for your quick response. i already encountered with this add-on. 

would it be possible for you to simulate this and let me know the step-by-step process  how to do it ?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...