Security

How to take mcafee virus scan and endpoint security version information into account?

SarahSplunk123
Explorer

Hello,

The EPOProdPropsView_VIRUSCAN fields are not present in the new version of McAfee : Endpoint Security replaces Virus Scan. Therefore, we cannot access the version data anymore, which is a problem for security logs analysis.
We have seen an answer which brings a partial solution to our problem:
https://answers.splunk.com/answers/626506/moving-from-mcafee-vse-to-ens.html
However, the two versions are currently being used, we need the query to take both into account.

Could the Splunk team who develops the McAfee addon update the query to take both versions into account?

Thanks

Best regards,

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!