Getting Data In

Best way to get Symantec AV data - (reworking an old instance of Splunk)

mhuntington
Explorer

Hello,

I am new to Splunk and was recently given our organization's old Splunk project. Long story, but basically it's been sitting idle for about 6 years.

The first thing I want to do is gather information on our Symantec updates. When Splunk was originally installed consultants used a SQL Server Agent workaround, I guess they couldn't get Symantec to play nice at the time.

I was hoping someone could point me in a good direction for this. What is the best option for this, apps or something else? Is there an app for Symantec?

Tags (1)
0 Karma

ryanoconnor
Builder

I've onboarded Symantec Endpoint Protection logs a number of times and this app is very great:

https://splunkbase.splunk.com/app/2772/

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...