Hello @User17662387
Thanks for your post.
ePO can forward received threat events directly to a syslog server, which is defined in ePO as a Registered Server.
https://kc.mcafee.com/corporate/index?page=content&id=KB87927
https://kc.mcafee.com/corporate/index?page=content&id=KB91194
Also this can be achieved with ePO Cloud
I hope the above will help you.
Was my reply helpful?
If you find this post useful, Please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Hi Thanks for your response.
But above two KB are for syslog integration and below one is for MVISION.It is CASB solution. These all are not applicable in my environment.
We have ePO deployed on AWS cloud and requirement is to send logs from ePO to AWS Security HUB direct or indirect way.
Thanks for your understanding.
Hello @User17662387
Thanks for your response.
Afaik This can not be achieved but i will check with @cdinet
I believe she can guide us in right direction and will also able to tell whether this can be done or not.
Was my reply helpful?
If you find this post useful, Please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Is epo on prem, mvision or cloud? With on prem, only options are syslog registered server or connect to db as siem. I don't know anything about aws security hub to answer, to be honest. If you are using mvision or cloud, there are api's that can pull events. Check here for any info on that.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA