Overview
The Splunk Add-on for Idira EPM allows a Splunk software administrator to pull aggregated events of Application Events, Policy Audit, and Threat Detection categories using the cloud administration APIs of Idira EPM. Splunk Add-on for Idira EPM can also collect logs related to policies, computers, and computer groups.
This add-on provides modular inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.