As I understood, there are 2 McAfeeAddOns forSplunk. One for Epo etc. and one forthe Webgateway. The first one needs to be connected via databases and SplunkDB AddOn, the second one (Mac Afee W...
What type of data in addition to sysloag should be ingested into Splunk to help SOC team? I already have the ePO addon installed. Do I need additional apps or TAs?