Skip to main content
Splunk Add-on for Symantec Endpoint Protection app icon

Splunk Add-on for Symantec Endpoint Protection

The Splunk Add-on for Symantec Endpoint Protection allows a Splunk® Enterprise administrator to collect server and client activity logs from Symantec Endpoint Protection Manager dump files. After Splunk Enterprise indexes the events, you can consume the data using the prebuilt dashboard panels included with the add-on. This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk Enterprise apps, such as the Splunk App for Enterprise Security and the Splunk App for PCI Compliance.

Built by Splunk LLC
splunk product badge

Default Version 2.0.1
June 26, 2015
Compatibility
Splunk Enterprise
CIM Version: 4.x
Rating

5

(1)

Log in to rate this app
Support
Splunk Supported
The Splunk Add-on for Symantec Endpoint Protection allows a Splunk® Enterprise administrator to collect server and client activity logs from Symantec Endpoint Protection Manager dump files. After Splunk Enterprise indexes the events, you can consume the data using the prebuilt dashboard panels included with the add-on. This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk Enterprise apps, such as the Splunk App for Enterprise Security and the Splunk App for PCI Compliance. This add-on must be installed on a Windows instance of Splunk Enterprise for data collection. The add-on is platform independent for indexers and search heads.

Categories

IT Operations, Security, Fraud & Compliance

Created By

Splunk LLC

Type

addon

Downloads

531

Featured in Collection

Staff Picks

Resources

Log in to report this app listing