Source types for the Splunk Add-on for Symantec DLP
The Splunk Add-on for Symantec DLP supports the following data source using the following collection methods and provides the following source type, event type, and CIM mapping.
Data source | Collection method | Source type | Event type | CIM data models |
---|---|---|---|---|
syslog data | File monitor or network (TCP/UDP) | symantec:dlp:syslog
|
symantec_dlp_alert
|
Alerts |
Lookups for the Splunk Add-on for Symantec DLP | Format specifications for event types for the Splunk Add-on for Symantec DLP |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!