Source types for the Splunk Add-on for McAfee ePO Syslog
The Splunk Add-on for McAfee ePO Syslog provides the index-time and search-time knowledge for intrusion prevention and malware scan data from the following formats.
Data format | Source Type | Description | CIM compliance |
---|---|---|---|
syslog
|
mcafee:epo:syslog
|
Contains McAfee ePO events collected via Syslog | Intrusion Detection, Malware |
Lookups for the Splunk Add-on for McAfee ePO Syslog | Troubleshooting |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!