Splunk® Supported Add-ons

Splunk Add-on for McAfee NSP

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Configure inputs for the the Splunk Add-on for McAfee NSP

Splunk Connect for Syslog

All production deployments should utilize Splunk Connect For Syslog to get syslog data into the Splunk platform. This solution provides improved simplicity and scalability, among other benefits. For more information, see https://splunk.github.io/splunk-connect-for-syslog/main/sources/vendor/McAfee/nsp/.

Validate data collection

Once you have configured the input, run this search to check that you are ingesting the correct expected data.

sourcetype=mcafee:nsp

Last modified on 11 May, 2023
PREVIOUS
Configure Network Security Manager to send syslog data to the Splunk Add-on for McAfee
  NEXT
Format specifications for event types with the Splunk Add-on for McAfee NSP release 1.1.0

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters