Solved! Go to Solution.
Hello @kotman
Thanks for your response.
Audit logs or any other logs are not forwarded by ePO to the Syslog receiver only threat events .
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hello @kotman
Thanks for your post.
Yes, You can configure a Syslog Server.
Use the below KB article:
https://kc.mcafee.com/corporate/index?page=content&id=KB87927
https://kc.mcafee.com/corporate/index?page=content&id=KB91194
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hello Vivs,
With syslog, we can send threat logs with event ids. McAfee ePO Audit Logs have no event id. Can we send only audit logs as syslog?
Best Regards
Hello @kotman
Thanks for your response.
Audit logs or any other logs are not forwarded by ePO to the Syslog receiver only threat events .
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
I know this is old, but I can confirm this. The only way we could figure out how to pull required logs is to either:
a) Log on to the console directly and execute reports (or view existing dashboards)
b) Use a tool which is capable of hooking in to the database and pulling information based off of SQL provided from an applicable report.
For things like successful or failed logins, it would be tolerable if logs were at the least in flat files on the system. But they are not. So chalk one up to making something easy, hard.
To paraphrase my parents, I am not upset it is like this, but it is disappointing.
You can also easily create a query for audit events, then run a server task periodically that runs that query and can email the report to anyone.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA