Splunk® Supported Add-ons

Splunk Add-on for McAfee ePO Syslog

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release notes for the Splunk Add-on for McAfee ePO Syslog

Version 1.1.0 of the Splunk Add-on for McAfee ePO Syslog was released on August 22, 2022.

Features

  • Support for latest CIM v5.0.1
  • Support for McAfee Endpoint Security 10.7.x & McAfee Agent 5.5.x
  • Enhanced CIM field mappings and increased coverage

Compatibility

Version 1.1.0 of the Splunk Add-on for McAfee ePO Syslog is compatible with the following versions, platforms, and products.

Splunk platform versions 8.1, 8.2, 9.0
CIM 5.0.1
Platforms Platform Independent
Vendor Products
  • McAfee Endpoint ePO v5.10
  • McAfee Endpoint Security
    • v10.6.0
    • v10.6.1
    • v10.6.1.1607
    • v10.7.0
    • v10.7.0.1285
    • v10.7.0.3255

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

Known issues

Version 1.1.0 of the Splunk Add-on for McAfee ePO Syslog contains the following known issues.

If no issues appear below, no issues have yet been reported.


Third-party software attributions

Version 1.1.0 of the Splunk Add-on for McAfee ePO Syslog does not incorporate any third-party software or libraries.

Last modified on 07 September, 2022
PREVIOUS
Troubleshooting
 

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters