MVISION ePO and insightIDR integration

Could anyone please share information about MVISION ePO integration with insightIDR?

Can we expect such integration in the future or MVISION is not particular popular?

MVISION ePO is cloud based product.
Unlike McAfee ePO events from MVISION are pulled via API.

Many thanks

1 Like

Hi @krasimir_ivanov,

MVISION today has not been particularly popular for us as an event source.

Based on your comments, would it be then safe to say that MVISION is the same as ePO, except that it is cloud based instead of on-premise?
Allow me to ask our event source team about this one.

Sincerely,
Felipe

Hi Felipe,

Thank you for your replay.

Based on your comments, would it be then safe to say that MVISION is the same as ePO, except that it is cloud based instead of on-premise?

Yes, the idea behind MVISION ePO is to provide very similar functionality as the on premise ePO, but without requiring on premise infrastructure.

Regards,
Krasi

I’m also looking for better integration with MVision ePO and MVision suite in general.

Hi Rodney,

this enhancement request has come up at least once before, I can see we have an existing IDEA (Enhancement Request) ticket on the backlog. Unfortunately we have no ETA commitment to provide right now.

David

We are looking for this as well, an ETA would be appreciated.

2 Likes

Any updates on this?

Hello,
We are still waiting on an ETA

Hi all, sorry for lack of updates on this one.

As of this week, we’ve an engineer looking into an integration with McAfee MVISION ePO.

One question, are there any types of logs in particular that you’d like from this event-source? (Just so our engineer can have this in mind when reviewing documentation).

It is worth noting that building an integration like this does take some time, but we’d expect to have this in product for Q3.

1 Like

I want to inquire if this is rolled out already, and if so do we have documentation for this?

1 Like

Hi everyone, I want to inquire if the integration of mcafee mvision to insightIDR is already available?

Thanks

I am also interested. Any progress in development ?

Hello everyone, checking for any development for this too.

Hope we get a positive response.

Hi all,

So this work was initially researched by engineering, but was paused for other event source related work.

I’ve a call with our engineering team next week to discuss how we progress this again. We’ll need sample logs to help build out parsing rules, so I will follow up next week to let you know the easiest way of getting these sent over to us.

Apologies on behalf of the team for delay on this one but hopefully we’ll be able to get an ETA on delivery in coming weeks.

Any questions in the meantime just let me know.

Thanks,
Cathal

1 Like

Hi all,

One of our engineers is ready to start work on integration - wondering would you be willing to send over sample logs through Kiteworks or give our team Dev Access to speed up work?