> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/log-forward/mcafee-epo.md).

# McAfee ePO

**McAfee ePO Log Integration Guide**

**To configure syslog:**

1. From the top left corner of your main McAfee console, select **Menu > Configuration > Registered Servers.**

<figure><img src="/files/ygKGMFmg1gGNldoGMN3B" alt=""><figcaption></figcaption></figure>

2. Click the **New Server** button.
3. From the Server type dropdown, select the **Syslog Server** option. Specify a unique name and any details and click the **Next** button.
4. On the Registered Server Builder page, use the “Server Name” field to provide the domain name, such as mycompany.com and the FQDN or IP address of the SIEM (InsightIDR) collector.
5. In “TCP port number,” provide the unique TCP port you have open for syslog.
6. Check the **Event Forwarding** box to enable syslog event forwarding from the McAfee Agent Handler to the SIEM (InsightIDR) collector.
7. To test the connection between McAfee ePO and the Collector, click the **Test Connection** button to verify the connection to your Collector.&#x20;
8. Click the **Save** button.                                                                                                                   **NOTE :** After you register the syslog server, you must set McAfee ePO to send specific events to your syslog server.
9. Navigate to **Menu > Policy > Server Settings.**
10. Select the **Event Filtering** option and click the **Edit** button in the bottom right of the page.

<figure><img src="/files/4FF6cr7iDKNvq9pbiUJY" alt=""><figcaption></figcaption></figure>

11. To tell the McAfee Agent what to forward, select the **only selected events to the server** button to choose from all available event IDs.

<figure><img src="/files/hx0abi535vNCF2Wzqzkm" alt=""><figcaption></figcaption></figure>

12. While SIEM (InsightIDR) will only parse events related to Malware or virus scanning, you can choose to send whichever events you want.
13. In “Where to store events,” keep the the **Store selected in both** option to forward information to a SIEM and to keep the data in your ePO database.
14. In “Event source,” select the **Events from any source** option.
15. Click the **Save** button.
