Hello,
I have Splunk 6.3.1 running on a single Linux instance. I have installed the Splunk Add-on for Symantec Endpoint Protection V2.1.0 , setup my SEP 12 server to dump logs, forward logs from sep server to Splunk server to a new "symantec" index. I am seeing all of my logs and parsing is looking great.
Is there something special I need to do to activate the Dashboards? I dont see them anywhere.
Thanks
↧