Can we send end point DNS query logs collected and send to McAfee SIEM for traffic flow view. Need to configure DNS query logs on ePO.
Please be more specific. ePO only uses dns for its lookups, so I am not sure exactly what you are trying to accomplish. There are no events for dns that are sent to the database for any siem to pick up.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hi, can we forward logs that has dns information from EPO to McAfee SIEM, rather than sending all logs to McAFee SIEM from EPO 5.9
The Siem can be configured to query for what you choose, from my understanding. You would have to get with the siem team for how to configure it for what you want. But I am still unclear on what type of events containing dns you are referring to. You need to clarify exactly what you are looking to accomplish and exactly what type of dns info you mean.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA