Hello all, I am trying to integrate trendmicro iwsva logs to splunk. It is showing as a supported device but i am unable to find any TA . Can someone suggest how to procees. Currently I have DDA/DDI logs being ingested for which the logs are properly parsed.I am using the same sourcetype for iwsva logs aswell i.e. cefevents
Can someone please suggest what should I use here. Thanks in advance for the help
If there are no suitable TAs available in splunkbase then the only alternative is to create your own. However, if the data is being parsed properly then it would seem you have a working TA already.
@richgalloway I can do that, but just wanted to know if anyone has worked on the trendmicro IWSVA logs and is aware of the souretype that should be used.
Thanks
Hello experts, for IWSVA , is there any specific sourcetype that we can select.