As per my opinon their support is really worst. This is what Splunk support is saying. As Support will be handling Break & Fix issues, we don't have any documentation on how to integrate Symantec Endpoint Protection logs with the Splunk Cloud. As informed, kindly reach out to AOD(Admin On Demand) team by contacting your Account Owner. They will be assisting you with all the required documents and further assistance. Hope you understand the same. Let us know how to proceed further on this case.
... View more