Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
Trellix ePO All in one app icon

Trellix ePO All in one

Non official Splunk Technology Add-on for integrating Trellix (McAfee) ePO security telemetry into Splunk. This add-on provides comprehensive data collection, CIM normalization, and a powerful all-in-one security dashboard.

Built by
splunk product badge
screenshot
screenshot
screenshot
screenshot
screenshot

Latest Version 1.1.2
January 13, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1, 8.0
CIM Version: 6.x, 5.x, 4.x, 3.x
Rating

0

(0)

Log in to rate this app
Support
Trellix ePO All in one support icon
Developer Supported addon
The Trellix (McAfee) ePO Splunk Technology Add-on enables Splunk users to reliably collect, normalize, and analyze security telemetry from Trellix ePolicy Orchestrator (ePO) in one centralized platform. Many organizations running Trellix ePO lack a native, CIM-compliant integration with Splunk, making it difficult to correlate endpoint security data with other security and IT signals. This app addresses that gap by providing a production-ready integration that ingests threat events, malware detections, endpoint and agent health, policy compliance, quarantine activity, updates, and user audit logs via the ePO REST API (and syslog where applicable). All data is normalized to the Splunk Common Information Model (CIM), allowing immediate use with Splunk Enterprise Security, Security Essentials, and custom SOC workflows. By combining secure data collection, enterprise-grade reliability, and a comprehensive all-in-one security dashboard, the add-on helps SOC teams, security engineers, and Splunk administrators gain clear visibility into endpoint threats, compliance posture, and operational health—without building and maintaining custom integrations. Note: This is a community-maintained, non-official add-on. It is not affiliated with Splunk or Trellix. "/sarat1kyan/TA-trellix-epo"

Categories

Endpoint, SIEM

Created By

Mher Saratikyan

Type

addon

Downloads

5

Resources

Log in to report this app listing