Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

TA customization for CEF input instead of vendors

$
0
0
Hi, I'm looking for the best way to make CEF events what Splunk receives from various vendors to adopt to Splunk's TAs For example: I've Websense Web Filter and Symantec Endpoint Protection. Splunk provides TAs for those products with CIM-compatible knowledge. I limited in receiving events from those products via CEF format. I want to customize Splunk TAs https://splunkbase.splunk.com/app/2966/ https://splunkbase.splunk.com/app/2772/ with input from CEF. What is the best way to do it?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>