Configure threat data report
This section is optional and provides insight into retrieving
CylancePROTECT Desktopdata only once per day, as opposed to the syslog data feed, which is real-time. For those that cannot consume syslog data (or want both data sources), the
CylancePROTECT DesktopApplication for
Splunkprovides the Threat Data Report-based sourcetypes, such as threats and devices.
To enable data of these sourcetypes, you will need to configure your app to match your
Cylanceconsole settings, such as the Threat Data Report download URL and the current Threat Data Report token.
To configure tenants, go to the application’s Help menu and select Configure TDR, which should take you to the following URL:
Tenant information is available in the console on the
Settings/Applicationpage, using the information below.