All Apps and Add-ons

any mcafee network security manager users?

mcbradford
Contributor

We are using McAfee Network Security Manager. We are using the option to send alerts out via syslog. Not all the fields are available, but they are in the mysql db. Has anyone worked on a good sql select to pull most of the alert data per event?

Tags (3)
0 Karma

pedrolito
Explorer

Hello,

I know topic is quiet old, but I currently have the same problem with NSM, so I up this one.

I can't manage to get clear information regarding actions taken by the IPS. I have added variables I need from the McAfee manager, but still can't find the one related to the action.

The Mcafee documentation found [here][1] gives some details, but I would simply modify my props.conf to get actions such as "blocked" and "allowed". And after reading this documentation, I am not able to add an action field for each situation.

FI, I am currently making my McAfee logs IDS CIM Compliant.

Any idea/feedback/rectification would be greatly appreciated !

Thx

0 Karma

tmeader
Contributor

We use the NSM product. You want to directly query the NSM's DB from Splunk as an input? Given our throughput, we'd never be able to do that in a real-time manner (the NSM's are slow enough as it is). Which fields are you looking for that aren't in the log messages (note that you CAN customize the log message format)?

0 Karma

mcbradford
Contributor

Are you on the latest version. I would like to get src/dest country and reputation, plus some of the application identification fields (layer 7 stuff). Past 24 hours 72k events. With proventia 96k past 24 hours and we poll the db for events.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...