Hi,
Could somoene please tell me the best rising column to use with the McAfee? I had it on timestamp but found I was getting lots of duplicate events indexed, would AutoID be a better option? I'm using DB Connect 3 and it otherwise seems to be working.
Thank you.
Hi,
This may help you:
http://docs.splunk.com/Documentation/AddOns/released/McAfeeEPO/ConfigureDBConnectv2inputs