Hi, we recently configured our ePO to forward events to syslog. The DLP data is showing in Splunk, however, we noticed that the fields are limited.
For example, for a Removable Storage incident, these are the fields that are showing up in Splunk:
In ePO, when digging into a Removable Storage incident, these fields (from Additional Information) are not showing up in Splunk:
For a Cloud Protection incident, this field is not showing up in Splunk: Cloud Service.
These are the DLP events selected. Wish it was easier to go through what events are being sent out as it is a long list. A filter perhaps for Agent, DLP, ENS, ATP, etc.
19136: McAfee DLP Endpoint User Sessions (Info)
19402: McAfee DLP Prevent Registered (Info)
See if this helps any, otherwise you might want to contact dlp team.
KB93612
https://community.mcafee.com/t5/Data-Loss-Prevention-DLP/bd-p/data-loss-prevention
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thank you @cdinet for the KB info.
Based on the attached files in that KB, the DLP events do not seem to forward everything when a DLP incident is generated.
We're trying to get out of the DB query/connect as this is custom, joining tables can be daunting when you're not a DBA. Unfortunately, the support team won't touch an SR when we need assistance when it comes to custom DB query.
So, I'm leveraging this forward feature from ePO to syslog. Disappointing to initially see that the forwarded DLP events are limited. It's looking like we have to go back to modifying our DB queries to get this information to Splunk.
Let me move this over to dlp team to see if they have any other suggestions.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: