Configure Network Security Manager to send syslog data to the Splunk Add-on for McAfee
To enable the Splunk Add-on for McAfee NSP to collect data from McAfee Network Security Manager, you need to configure McAfee Network Security Manager to send the events using syslog in custom format to the data collection node of your Splunk platform installation. Splunk best practice is to use SC4S.
Enable Syslog for Firewall Access Events
- Navigate to Manager -> <Admin Domain> -> Setup -> Notification -> Firewall Access Events
- Select "Yes" for the "Enable Syslog Notification" option
- Provide all the necessary and relevant information and click Save
- After saving the changes, "System Default" and "Customized" message body options are available. Select the "Customized" option and click on "Edit".
- Enter the customized event format for Firewall Events and click on Save.
- Click on "Save" again on the Firewall Access Events page for saving all the changes.
Enable Syslog for Alert Events
- Navigate to Manager -> <Admin Domain> -> Setup -> Notification -> IPS Events -> Syslog
- Select "Yes" for the "Enable Syslog Notification" option and click on Save
- Create a Syslog Notification Profile by clicking on "+" and provide all the necessary and relevant information.
- Enter the customized event format for Alert Events and click on Save
Enable Syslog for Fault Events
- Navigate to Manager -> <Admin Domain> -> Setup -> Notification -> Faults -> Syslog
- Select "Yes" for the "Enable Syslog Notification" option
- Provide all the necessary and relevant information and click Save
- After that, you are provided an option for System Default or Customized Message Preference. Select the "Customized" option and click on Edit.
- Enter the customized event format for Fault Events and click on Save.
- Click on "Save" on the Fault Syslog page for saving all the changes.
Enable Syslog for Audit Events
- Navigate to Manager -> <Admin Domain> -> Setup -> Notification -> User Activity -> Syslog
- Select "Yes" for the "Enable Syslog Notification" option
- Provide all the necessary and relevant information
- Click on Apply. After that, you are provided an option for System Default or Customized Message Preference. Select the "Customized" option and click on Edit.
- Enter the customized event format for Audit Events and click on Save.
- Click on "Save" on the Audit Syslog page for saving all the changes.
See Format specification for different types of events for a customized event format.
Install the Splunk Add-on for McAfee NSP | Configure inputs for the the Splunk Add-on for McAfee NSP |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!