Management Center and Reporting

 View Only

 Splunk integration after last SEPC update

Ninjavi's profile image
Ninjavi posted Nov 12, 2020 05:30 AM

Hello everyone,

We were using the official scripts recommended in the following support link: https://help.symantec.com/cs/SEPC/SEPC/v126173001_v101064224/Importing-SEP-Cloud-events-into-Splunk-or-other-applications?locale=EN_US

To resume, those scripts are:
SEPCloudConfig.ini - Contains Client ID and Secret Key.
wrapper.sh - Just a caller to the python script.
ExportClient.py - To get the events contacting the API, etc.

Therefore, since the SEPC has been updated, even creating a new Client ID and Secret Key and replacing both of them in the SEPCloudConfig.ini configuration, event ingestion into Splunk is not working anymore.

There are no errors while executing ExportClient.py, but there are no events to export.

We are still using both old and the new portal, but only the security events from the old portal are ingested successfully.
By the way, scripts are not available to download anymore.

Is there another way to ingest SEPC events into Splunk or something that needs to be updated in the old scripts, apart from the new Client ID and Secret ID?

Thanks in advance,

Kind regards,

Jacob Miles's profile image
Broadcom Employee Jacob Miles
Hi Ninjavi,

Thank you for question. This community is actually not for Splunk questions, but actually the Symantec Reporter appliance that ingests ProxySG logs. My recommendation, if you haven't already, would be to ask this on the SEP Cloud community.

Thanks!