<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Arcsight 2 Splunk Transition in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534729#M9616</link>
    <description>&lt;P&gt;Splunk has an entire Professional Services practice for this so it's not something that is easily summarized in a forum posting.&amp;nbsp; That's also why documentation is hard to come by.&lt;/P&gt;&lt;P&gt;You'll want the Splunk Enterprise Security app.&amp;nbsp; It's a premium product (extra cost), but is what Splunk offers as a SIEM.&amp;nbsp; Replacing ArcSight with core Splunk is likely to lead to disappointing results.&lt;/P&gt;&lt;P&gt;The first step in the transition is to install Splunk and start sending your data to it.&amp;nbsp; You should be able to send the data to both ArcSight and Splunk simultaneously.&lt;/P&gt;&lt;P&gt;Next, you'll need to map your ArcSight rules to Splunk searches.&amp;nbsp; Run the searches and compare the results to those reached by ArcSight.&amp;nbsp; Adjust the searches until you get the desired results.&lt;/P&gt;&lt;P&gt;Use ArcSight and Splunk side-by-side for a while to confirm Splunk is acting as expected.&amp;nbsp; Once you're confident in it, shut down ArcSight.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2021 18:32:00 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-01-04T18:32:00Z</dc:date>
    <item>
      <title>Arcsight 2 Splunk Transition</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534727#M9615</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Looking for new resources to transition from ArcSight to Splunk please. The resources found on Micro Focus site are very old. Links &amp;amp; docs are much appreciated. If you have done this before any Do's &amp;amp; Don't are welcomed. Thank u&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 17:39:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534727#M9615</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-01-04T17:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Arcsight 2 Splunk Transition</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534729#M9616</link>
      <description>&lt;P&gt;Splunk has an entire Professional Services practice for this so it's not something that is easily summarized in a forum posting.&amp;nbsp; That's also why documentation is hard to come by.&lt;/P&gt;&lt;P&gt;You'll want the Splunk Enterprise Security app.&amp;nbsp; It's a premium product (extra cost), but is what Splunk offers as a SIEM.&amp;nbsp; Replacing ArcSight with core Splunk is likely to lead to disappointing results.&lt;/P&gt;&lt;P&gt;The first step in the transition is to install Splunk and start sending your data to it.&amp;nbsp; You should be able to send the data to both ArcSight and Splunk simultaneously.&lt;/P&gt;&lt;P&gt;Next, you'll need to map your ArcSight rules to Splunk searches.&amp;nbsp; Run the searches and compare the results to those reached by ArcSight.&amp;nbsp; Adjust the searches until you get the desired results.&lt;/P&gt;&lt;P&gt;Use ArcSight and Splunk side-by-side for a while to confirm Splunk is acting as expected.&amp;nbsp; Once you're confident in it, shut down ArcSight.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 18:32:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534729#M9616</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-04T18:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Arcsight 2 Splunk Transition</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534745#M9617</link>
      <description>&lt;P&gt;I appreciate your response &amp;amp; Thank you for your time. I have a couple of questions&amp;nbsp;&lt;/P&gt;&lt;P&gt;What role does the Splunk Ent. Security app has with such transition?&lt;/P&gt;&lt;P&gt;Would you elaborate on mapping Arcsight rules to Splunk searches a bit &amp;amp; where such instructions are found.&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 02:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534745#M9617</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-01-05T02:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Arcsight 2 Splunk Transition</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534812#M9618</link>
      <description>&lt;P&gt;Splunk Enterprise Security is Splunk's SIEM product.&amp;nbsp; It is the replacement for ArcSight.&lt;/P&gt;&lt;P&gt;I'm not aware of any instructions for mapping ArcSight rules to Splunk searches.&amp;nbsp; It's probably a tedious manual process of looking at each ArcSight rule and then looking at each Splunk search to see which is a good match.&amp;nbsp; If a match is not found then write an equivalent Splunk search.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 15:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Arcsight-2-Splunk-Transition/m-p/534812#M9618</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-05T15:15:46Z</dc:date>
    </item>
  </channel>
</rss>

