For the complete documentation index, see llms.txt. This page is also available as Markdown.

McAfee ePO

McAfee ePO Log Integration Guide

To configure syslog:

  1. From the top left corner of your main McAfee console, select Menu > Configuration > Registered Servers.

  1. Click the New Server button.

  2. From the Server type dropdown, select the Syslog Server option. Specify a unique name and any details and click the Next button.

  3. On the Registered Server Builder page, use the “Server Name” field to provide the domain name, such as mycompany.com and the FQDN or IP address of the SIEM (InsightIDR) collector.

  4. In “TCP port number,” provide the unique TCP port you have open for syslog.

  5. Check the Event Forwarding box to enable syslog event forwarding from the McAfee Agent Handler to the SIEM (InsightIDR) collector.

  6. To test the connection between McAfee ePO and the Collector, click the Test Connection button to verify the connection to your Collector.

  7. Click the Save button. NOTE : After you register the syslog server, you must set McAfee ePO to send specific events to your syslog server.

  8. Navigate to Menu > Policy > Server Settings.

  9. Select the Event Filtering option and click the Edit button in the bottom right of the page.

  1. To tell the McAfee Agent what to forward, select the only selected events to the server button to choose from all available event IDs.

  1. While SIEM (InsightIDR) will only parse events related to Malware or virus scanning, you can choose to send whichever events you want.

  2. In “Where to store events,” keep the the Store selected in both option to forward information to a SIEM and to keep the data in your ePO database.

  3. In “Event source,” select the Events from any source option.

  4. Click the Save button.

Last updated