Use the Splunk Add-on for Symantec Endpoint Protection (SEP) to collect SEP server and client activity logs from:
Built by
Latest Version 4.0.0
September 30, 2025
Compatibility
This is compatibility for the latest version
Not Available
Platform Version: 10.0, 9.4, 9.3, 9.2
CIM Version: 6.x
Rating
0
(0)
Log in to rate this app
Support
Splunk Supported addon
Ranking
#42
in Security, Fraud & Compliance
#45
in IT Operations
Use the Splunk Add-on for Symantec Endpoint Protection (SEP) to collect SEP server and client activity logs from:
- Symantec Endpoint Protection Manager dump files
- Syslog, using Splunk forwarders and Splunk Connect for Syslog
You can collect the following log files:
- Server Administration
- Application and Device Control
- Server Client
- Server Policy
- Server System
- Client Packet
- Client Proactive Threat
- Client Risk
- Client Scan
- Client Security
- Client System
- Client Traffic