Skip to content

Commit

Permalink
Update Symantec EP document
Browse files Browse the repository at this point in the history
  • Loading branch information
Mahir Chavda committed May 7, 2020
1 parent b56083e commit 695de26
Showing 1 changed file with 21 additions and 9 deletions.
30 changes: 21 additions & 9 deletions docs/sources/Symantec/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,15 +10,27 @@

### Sourcetypes

| sourcetype | notes |
|----------------|---------------------------------------------------------------------------------------------------------|
| symantec:ep:syslog | Warning the syslog method of accepting EP logs has been reported to show high data loss and is not Supported by Splunk |

### Sourcetype and Index Configuration

| key | sourcetype | index | notes |
|----------------|----------------|----------------|----------------|
| symantec_ep | symantec:ep:syslog | epav | none |
| sourcetype | notes |
|--------------------------------|---------------------------------------------------------------------------------------------------------|
| symantec:ep:syslog | Warning the syslog method of accepting EP logs has been reported to show high data loss and is not Supported by Splunk |
| symantec:ep:admin:syslog | none |
| symantec:ep:agent:syslog | none |
| symantec:ep:agt:system:syslog | none |
| symantec:ep:behavior:syslog | none |
| symantec:ep:packet:syslog | none |
| symantec:ep:policy:syslog | none |
| symantec:ep:proactive:syslog | none |
| symantec:ep:risk:syslog | none |
| symantec:ep:scan:syslog | none |
| symantec:ep:scm:system:syslog | none |
| symantec:ep:security:syslog | none |
| symantec:ep:traffic:syslog | none |

### Index Configuration

| key | index | notes |
|----------------|----------------|----------------|
| symantec_ep | epav | none |


### Filter type
Expand Down

0 comments on commit 695de26

Please sign in to comment.