Refine your search:

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

Symantec Endpoint Protection Reporting - some high level reporting around logs sent to Splunk from the SEP console. This application is pretty basic, so any requests / comments would be appreciated.

Screenshots

http://dl.dropbox.com/u/6408771/SEP_Application/ScreenShot_1.JPG
http://dl.dropbox.com/u/6408771/SEP_Application/ScreenShot_2.JPG

Overview

This is a pretty basic application, allowing some high level visibility into Symantec Endpoint Protection logging.

It consists of the following:

One Saved Search:
sep_virusfound_alert -> Looks for virus alerts in the logs, and emails it out. We use this to allow the help desk to stay on top of virus issues. Not enabled by default

Two Views:
"SEP Statistics" -> Some various overall statistics for SEP over all.
"SEP System Details" -> Allows you to search by system name to get various information about it such as scan history, Virus history and general SEP logs about that system

Twenty-Three different event types

Installation Instructions

Install via Splunkbase -OR- download, and extract it to $SPLUNK_HOME/etc/apps

If you use an index other then "prod_sep_logs" (which I expect most do)
Copy $SPLUNK_HOME/etc/apps/SEP_Reporting/default/eventtypes.conf to $SPLUNK_HOME/etc/apps/SEP_Reporting/local/eventtypes.conf

Modify $SPLUNK_HOME/etc/apps/SEP_Reporting/local/eventtypes.conf and replace "prod_sep_logs" with your index name.

You will also need to modify the sourcetype if you are using something other then prod_sep_log!
Modify $SPLUNK_HOME/etc/apps/SEP_Reporting/local/props.conf and change it to match your sourctype.

Restart Splunk

NOTE: I do not cover how to feed Splunk SEP logs. I actually had someone on my windows team do that for me and I didn't document it.

*NOTE Regarding SEP Version*
Please note this application was quickly thrown together over a year ago as one of my first requests after rolling out Splunk. My company currently runs SEP 11, and the application still generates usefull reports.

Unfortunately, I don't have time or the environment to modify this around new versions of SEP as they are released.

Brian

Versions and Release Notes

Version 1.1 (current version - updated Dec 19, 2011)
release notes:
Removed references to my account in the app.
show older versions »
Version 1.0 (updated Dec 23, 2010)

posted 23 Dec '10, 18:39

Brian%20Osburn's gravatar image

Brian Osburn
2.8k14
accept rate: 22%

new version 19 Dec '11, 19:05


6 Reviews:
0 ratings

We are running SEP 2012, but don't get anything found in the reports. I'm a bit of a n00b at Splunk, but understand regex well. So some hints from other users at what to look for and change and I should be able to get it going.

comments (0)

reviewed 07 Mar, 22:10

glenn2's gravatar image

glenn2
211
accept rate: 0%

edited 07 Mar, 22:11

You can install the Splunk Forwarder on the server, select all the Event Logs. The one that SEP uses is WinEventLog:Application. The default index for these on the splunk box is "main".

Our setup is pretty new, so we don't have any virus detections yet :)

comments (0)

reviewed 01 Mar, 21:11

glenn2's gravatar image

glenn2
211
accept rate: 0%

Hi Brian, I like the app as it provides a great way to consolidate events from the Symantec EndPoint console. Is it possible to modify the app so that provides "drill down" functionality from the "Statistics" dashboard. Currently I have to copy and pasted any data from this page to the "Details" page.

Thanks and I appreciate the effort you put into creating this Ap.

comments (0)

reviewed 17 Oct '11, 10:03

steveirogers's gravatar image

steveirogers
01
accept rate: 0%

I am new to Splunk, and since i have started to test the application, i began to find that i just don't like to log into multiple consoles for events, nor do i like to receive emails from multiple systems. This application solves the need to check multiple sources for SEP events, and does a great job at it!!

I had issues with the application, and the developer was very helpful with troubleshooting the issues. We use an older version of SEP,(11.0.6005.562), and it works perfectly with this application!

Brian, Thanks for creating such a great application!!!

comments (0)

reviewed 07 Oct '11, 07:46

sideone's gravatar image

sideone
1
accept rate: 0%

edited 07 Oct '11, 07:48

You can feed the splunk logs through your SEPM console. Setup external logging and point it to your splunk server. To make it easier I created a prod_sep_logs index and tied that index to 515/UDP. Now all my SEP data is coming to the correct database.

Don't forget to restart splunk after your changes.

There also appears to be a problem with the way Symantec log files in v15. I am working on editing the transforms and will post information as I progress.

comments (0)

reviewed 03 Aug '11, 08:05

jgolovich's gravatar image

jgolovich
11
accept rate: 0%

NOTE: I do not cover how to feed Splunk SEP logs. I actually had someone on my windows team do that for me and I didn't document it.

Isn't that a key part to this app?

comments (0)

reviewed 10 May '11, 12:55

MBerikcurtis's gravatar image

MBerikcurtis
652
accept rate: 25%

Your review

Did you find this app useful?

Preview toggle preview

Details

This app is not covered by any support agreements in place with Splunk. If you have questions about the installation or operation of this app, please contact the author.

Version 1.1
Last Updated: Dec 19, 2011
Download App
Author: Brian Osburn
Version: 1.1
Splunk compatibility: 4.3, 4.2, 4.1, 4.x
Price: Free
License: Creative Commons BY 3.0
Downloads: 993

Follow this app

Log In to enable email subscriptions

RSS:

Reviews

Reviews + Comments

Related Apps

 
Copyright © 2005-2012 Splunk, Inc. All rights reserved.