Configure inputs for the the Splunk Add-on for McAfee NSP
Splunk Connect for Syslog
All production deployments should utilize Splunk Connect For Syslog to get syslog data into the Splunk platform. This solution provides improved simplicity and scalability, among other benefits. For more information, see https://splunk.github.io/splunk-connect-for-syslog/main/sources/vendor/McAfee/nsp/.
Validate data collection
Once you have configured the input, run this search to check that you are ingesting the correct expected data.
sourcetype=mcafee:nsp
Configure Network Security Manager to send syslog data to the Splunk Add-on for McAfee | Format specifications for event types with the Splunk Add-on for McAfee NSP release 1.1.0 |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!