<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get data data from ArcSight Connectors in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109199#M7715</link>
    <description>&lt;P&gt;Hi woojacky,&lt;/P&gt;

&lt;P&gt;I will very happy if you can share with my the configuration we need to do for connecting our Arcsight to Splunk:&lt;/P&gt;

&lt;P&gt;how to define to with index arcsight events will written?&lt;/P&gt;

&lt;P&gt;how to define the right sourcetype so splunk can parse the data in the right way?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2016 07:58:18 GMT</pubDate>
    <dc:creator>omerr</dc:creator>
    <dc:date>2016-05-25T07:58:18Z</dc:date>
    <item>
      <title>How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109173#M7689</link>
      <description>&lt;P&gt;The &lt;A href="http://www.splunk.com/web_assets/pdfs/resources/Integrating_Splunk_with_Arcsight.pdf"&gt;integrating Splunk with Arcsight&lt;/A&gt; document, states it is possible to feed Splunk with data coming straight from a Connector. Do you have any idea how this is possible?&lt;/P&gt;

&lt;P&gt;The ArcSight website is not as full of infos as Splunk's...&lt;BR /&gt;
And, yes, I know this might not be the right community, but it's the one I happen to trust. &lt;/P&gt;

&lt;P&gt;Paolo&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2011 11:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109173#M7689</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2011-11-16T11:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109174#M7690</link>
      <description>&lt;P&gt;I highly recommend using &lt;A href="http://splunk-base.splunk.com/apps/22280/cef-common-event-format-extraction-utilities" target="_blank"&gt;http://splunk-base.splunk.com/apps/22280/cef-common-event-format-extraction-utilities&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;it parse the arcsight cef format quit easily&lt;/P&gt;

&lt;P&gt;as for time stamps extractions I recommend adding the following in the relevent stanza in porps.conf:&lt;/P&gt;

&lt;P&gt;TIME_PREFIX = \s(end|rt)\=&lt;/P&gt;

&lt;P&gt;TIME_FORMAT = %10S%3n &lt;/P&gt;

&lt;P&gt;MAX_TIMESTAMP_LOOKHEAD = 350&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109174#M7690</guid>
      <dc:creator>gooza</dc:creator>
      <dc:date>2020-09-28T10:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109175#M7691</link>
      <description>&lt;P&gt;If you meant how to configure the arcsight agent to send the data out to splunk ,   let me know and I'll send you instructions on how to ...&lt;/P&gt;

&lt;P&gt;run the command ..installdir\current\bin\arcsight agentsetup&lt;BR /&gt;&lt;BR /&gt;
choose yes to start the wizardmode&lt;BR /&gt;
choose I want to add/remove/modify arcsight Manager destinations&lt;BR /&gt;
choose add new destination&lt;BR /&gt;
choose raw syslog&lt;BR /&gt;
add the information of the splunk input you prepared choose the protocol.&lt;/P&gt;

&lt;P&gt;hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2011 11:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109175#M7691</guid>
      <dc:creator>gooza</dc:creator>
      <dc:date>2011-11-16T11:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109176#M7692</link>
      <description>&lt;P&gt;Hi, thanks for the reply. Yes, I meant how to configure the Connectors.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2011 11:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109176#M7692</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2011-11-16T11:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109177#M7693</link>
      <description>&lt;P&gt;Hi gooza. So, it is possible to configure an Arcsight Connector to send data to a 3rd party receiver in CEF over Syslog format. Thank you very much&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2011 12:03:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109177#M7693</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2011-11-16T12:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109178#M7694</link>
      <description>&lt;P&gt;Yes , I sent you the instructions how,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2011 12:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109178#M7694</guid>
      <dc:creator>gooza</dc:creator>
      <dc:date>2011-11-16T12:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109179#M7695</link>
      <description>&lt;P&gt;Just wondering: is it possible to forward CEF data to splunk from Logger itself to Splunk? This would limit the effort on the connectors as, I'm told, you need quite a number of them even for small environments&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2011 11:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109179#M7695</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2011-12-06T11:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109180#M7696</link>
      <description>&lt;P&gt;I'm a total noob, and trying to figured out how to configure the cef extraction utils app (&lt;A href="http://splunk-base.splunk.com/apps/22280/cef-common-event-format-extraction-utilities"&gt;http://splunk-base.splunk.com/apps/22280/cef-common-event-format-extraction-utilities&lt;/A&gt;) but cannot understand how to work it out&lt;/P&gt;

&lt;P&gt;Can you help out in understanding what does it mean to do the following:&lt;BR /&gt;
"Add REPORT-cefvenets = cefHeaders,cefKeys to relevant stanzas in order for this add-on to parse the events"&lt;BR /&gt;
what file should i edit?&lt;/P&gt;

&lt;P&gt;and secondly, can i apply the app on content that is loaded to splunk via the oneshot rest api?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2012 12:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109180#M7696</guid>
      <dc:creator>dotan_patrich77</dc:creator>
      <dc:date>2012-03-29T12:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109181#M7697</link>
      <description>&lt;P&gt;add to your props.conf file under the relevent stanza the row:&lt;BR /&gt;&lt;BR /&gt;
REPORT-cefevents = cefHeaders,cefKeys  &lt;/P&gt;

&lt;P&gt;you can read more on props.conf at&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf"&gt;splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2012 12:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109181#M7697</guid>
      <dc:creator>gooza</dc:creator>
      <dc:date>2012-03-29T12:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109182#M7698</link>
      <description>&lt;P&gt;Some updates to this thread&lt;BR /&gt;
The CEF app needs to be updated with some small corrections. It will work with any Splunk version 4.1 or later.&lt;/P&gt;

&lt;P&gt;Those corrections are listed below. props.conf and transforms.com will work nicely exactly as they are below.  All of these are minor improvements and corrections on the advice above.&lt;/P&gt;

&lt;P&gt;The default way to send data from an Arcsight Connector with be to a port. The default Arcsight Connector port is 8443&lt;/P&gt;

&lt;P&gt;This is what is should look like.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;props.conf
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;[cefevents]&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 350&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TIME_PREFIX = \s(end|rt)=&lt;BR /&gt;
pulldown_type = 1&lt;BR /&gt;
REPORT-cefevents = cefHeaders cefKeys&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;P&gt;[cefHeaders]&lt;BR /&gt;
REGEX = CEF:(?&lt;CEF_CEFVERSION&gt;\d+)|(?&lt;CEF_VENDOR&gt;[^|]&lt;EM&gt;)|(?&lt;CEF_PRODUCT&gt;[^|]&lt;/CEF_PRODUCT&gt;&lt;/EM&gt;)|(?&lt;CEF_VERSION&gt;[^|]&lt;EM&gt;)|(?&lt;CEF_SIGNATURE&gt;[^|]&lt;/CEF_SIGNATURE&gt;&lt;/EM&gt;)|(?&lt;CEF_NAME&gt;[^|]&lt;EM&gt;)|(?&lt;CEF_SEVERITY&gt;[^|]&lt;/CEF_SEVERITY&gt;&lt;/EM&gt;)&lt;/CEF_NAME&gt;&lt;/CEF_VERSION&gt;&lt;/CEF_VENDOR&gt;&lt;/CEF_CEFVERSION&gt;&lt;/P&gt;

&lt;P&gt;[cefKeys]&lt;BR /&gt;
REGEX = (?:_+)?(?&amp;lt;_KEY_1&amp;gt;[\w.:,[]]+)=(?&amp;lt;_VAL_1&amp;gt;.*?(?=(?:\s[\w.:,[]]+=|$||)))&lt;BR /&gt;
REPEAT_MATCH = True&lt;BR /&gt;
CLEAN_KEYS = 1&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:19:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109182#M7698</guid>
      <dc:creator>Claw</dc:creator>
      <dc:date>2020-09-28T12:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109183#M7699</link>
      <description>&lt;P&gt;Please ignore the REGEXES above, the editor screws them up.&lt;/P&gt;

&lt;P&gt;We will get the proper examples posted in &lt;A href="http://splunk-base.splunk.com/apps/22280/cef-common-event-format-extraction-utilities"&gt;CEF (Common Event Format) Extraction Utilities&lt;/A&gt; App&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2012 22:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109183#M7699</guid>
      <dc:creator>Claw</dc:creator>
      <dc:date>2012-08-24T22:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109184#M7700</link>
      <description>&lt;P&gt;Hi, I would appreciate if you can send me the ArcSight connector to SPLUNK configuration instruction. Also what is a good architecture for an MSSP environment, Sending data from connector to SPLUNK or sending data from Logger to SPLUNK?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2012 13:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109184#M7700</guid>
      <dc:creator>rakeshmukherjee</dc:creator>
      <dc:date>2012-10-15T13:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109185#M7701</link>
      <description>&lt;P&gt;Hello.  If you still have the configuration on setting up Splunk to receive data from Connectors that'll be awesome!  Can you send me a copy of your instructions?  Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 15:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109185#M7701</guid>
      <dc:creator>gwong3</dc:creator>
      <dc:date>2015-02-17T15:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109186#M7702</link>
      <description>&lt;P&gt;One option is to create a RAW syslog output destination on your ArcSight connector.  On your Splunk server use rsyslog or similar to listen for the incoming syslog feed from the ArcSight connector.  Use Splunk to monitor the file it writes.  The file is still written to if you stop or restart Splunk.&lt;/P&gt;

&lt;P&gt;Do you need more specific instruction?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2015 01:46:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109186#M7702</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2015-02-24T01:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109187#M7703</link>
      <description>&lt;P&gt;I'd also like the instructions please.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2015 15:50:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109187#M7703</guid>
      <dc:creator>cladkins</dc:creator>
      <dc:date>2015-03-04T15:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109188#M7704</link>
      <description>&lt;P&gt;Hi gooza, Please help me out how to configure arcsight agent to send data to splunk. &lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 09:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109188#M7704</guid>
      <dc:creator>ManoharChinnaiy</dc:creator>
      <dc:date>2015-08-12T09:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109189#M7705</link>
      <description>&lt;P&gt;Hey gooza, could you send me the instructions for me to have a look? Appreciate!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 02:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109189#M7705</guid>
      <dc:creator>woojacky</dc:creator>
      <dc:date>2015-11-12T02:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109190#M7706</link>
      <description>&lt;P&gt;Hi Gooza,&lt;/P&gt;

&lt;P&gt;Can you forward the document on how to configure the Arcsight agent to send data out to Splunk to me as well please?&lt;/P&gt;

&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 04:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109190#M7706</guid>
      <dc:creator>phil_wang</dc:creator>
      <dc:date>2016-03-24T04:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109191#M7707</link>
      <description>&lt;P&gt;Hey Phil, I didn't get any information from Gooza as well. Nevertheless I worked it out internally with my network folks to eventually send data to Splunk from Arcsight. If you can wait till next Friday when I am back in office I will gladly share the information to you.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 04:31:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109191#M7707</guid>
      <dc:creator>woojacky</dc:creator>
      <dc:date>2016-03-24T04:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data data from ArcSight Connectors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109192#M7708</link>
      <description>&lt;P&gt;If you use a connector appliance to manage your ArcSight connectors you can just add a new destination and point it at your Splunk server.&lt;/P&gt;

&lt;P&gt;Add Destination &amp;gt; Create a new destination &amp;gt; Raw Syslog.  Enter IP/Host, Port, Protocol (UDP), and select 'false' for metadata.&lt;/P&gt;

&lt;P&gt;Enable a UDP syslog listener on the port you specified for your destination and have Splunk read the file.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 13:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-data-data-from-ArcSight-Connectors/m-p/109192#M7708</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2016-03-24T13:06:20Z</dc:date>
    </item>
  </channel>
</rss>

