Azure-Sentinel-McAfee-MVision-ePO-Cloud
Azure Sentinel custom Data connector to ingest cloud based McAfee MVISION ePO Events
Pre-requisites
- Sign up for an MVISION ePO account: https://mvision.mcafee.com
- McAfee sends a user activation email and a welcome email containing the MVISION ePO URL. Activate your account before logging on to MVISION ePO
- Log on to MVISION ePO and deploy Endpoint Security to client systems
- Configure McAfee Event Receiver to use Threat Events API
- Generate Client Id
- Login to the MVISION EPO console and open a new tab
- Go to https://auth.ui.mcafee.com/support.html to retrieve your client_id