This App helps to setup and maintain McAfee Client Proxy (MCP) deployment.
During the MCP setup it is not just enough to install/deploy the MCP executable and configure proxy settings. Sooner or later some exceptions need to be configured. Usually (bad practice) exceptions are configured only after a user complains that something doesn't work. Much better way is to be proactive and to configure exceptions in advance.
This app allows to collect FireCore logs from one or many systems and shows which connections are being redirected to which proxies and which connections bypass proxy.
Discuss the Splunk App for McAfee FireCore on Splunk Answers at http://answers.splunk.com/answers/app/4763
This is a first public release, consider it Beta.
TA_McAfee_FireCore Add-On (https://splunkbase.splunk.com/app/4762/)
For a single desployment (to collect FireCore logs from one system only) you need to install Splunk Enterprise + TA_McAfee_FireCore Add-On + McAfee_FireCore App on the system where MCP is installed.
For a distributed desploymeint (to collect FireCore logs from many systems):
* install Splunk Universal Forwarder + TA_McAfee_FireCore Add-On on each client system where MCP is installed
* install Splunk Enterprise + TA_McAfee_FireCore Add-On + McAfee_FireCore App on a separate server to collect logs
* configure (if not yet done) input on Splunk Enterprise
* configure output on each Universal Forwarder
* restart Universal Forwarder to enable FireCore Logging
This app tested for MCP 2.x and 3.x version on x64 Windows platform.
*mcpservice.exe process cannot be filtered out.
*enable name resolution for ip addresses.
0.0.6 - minor fixes, CIM compatibility
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.