Skip to main content
Splunk Add-on for Symantec Endpoint Protection app icon

Splunk Add-on for Symantec Endpoint Protection

Use the Splunk Add-on for Symantec Endpoint Protection (SEP) to collect SEP server and client activity logs from:Built by Splunk LLC
splunk product badge

Default Version 4.0.0

September 30, 2025

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2

CIM Version: 6.x

Rating
2
(16)

Log in to rate this app

Support
Splunk Supported
Ranking

#44 in IT Operations

#45 in Security, Fraud & Compliance

Use the Splunk Add-on for Symantec Endpoint Protection (SEP) to collect SEP server and client activity logs from: - Symantec Endpoint Protection Manager dump files - Syslog, using Splunk forwarders and Splunk Connect for Syslog You can collect the following log files: - Server Administration - Application and Device Control - Server Client - Server Policy - Server System - Client Packet - Client Proactive Threat - Client Risk - Client Scan - Client Security - Client System - Client Traffic