cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Setting Up Syslog

Hi there, I was looking to get some assistance in syslogging DLP events to our SIEM. I did setup syslog as a Registered Server, but these messages are encrypted and my SIEM has them garbled. We'd like to know how we can get around this, or alternatively query the SQL database to pull in user activity information with a SQL query. We need to have incidents monitored in our SIEM as soon as possible. Please and thanks.
2 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Setting Up Syslog

Since DLP endpoint is based on ePO and ePO is installed on a Windows machine, you cannot work with syslog, you probably will have to install an agent/connector of that SIEM solution.

Highlighted

Re: Setting Up Syslog

Start by creating an ePO DLP Incident query based on the data you are looking to build a SQL query on. 

There is an option in ePO to view the details of a saved query. Under “Actions” you can “View SQL” to get a database query of the selected ePO query. 

The “View SQL” action give you the SQL query that was used by ePO to generate the ePO query.

From there, you can look into the database structure to include additional information from other tables that are not available from a normal ePO DLP query. Unfourtunately, this is neccesary if you want more specific information from certain types of DLP events. 

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community