<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcSight and Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ArcSight-and-Splunk/m-p/91435#M19013</link>
    <description>&lt;P&gt;Have a look at this document.  &lt;A href="http://www.splunk.com/web_assets/pdfs/resources/Integrating_Splunk_with_Arcsight.pdf" target="_blank"&gt;http://www.splunk.com/web_assets/pdfs/resources/Integrating_Splunk_with_Arcsight.pdf&lt;/A&gt;  While this provides the basics, I believe that more in depth work would be needed to properly map the Windows audit logs.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 14:42:01 GMT</pubDate>
    <dc:creator>mlulmer</dc:creator>
    <dc:date>2020-09-28T14:42:01Z</dc:date>
    <item>
      <title>ArcSight and Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ArcSight-and-Splunk/m-p/91433#M19011</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;From you earlier post, I understand that you have integrated Splunk with ArcSight and so I would request if you please help me to understand a few question here,&lt;/P&gt;

&lt;P&gt;What should be the SIEM architecture in a scenario where I have ArcSight Manager, Logger and connector and now I want to integrate Splunk for long term data retention purpose. I find that long term data retention is not a good cost effective option with ArcSight Logger and also searching performance is very slow in archived data since it does not contain index information. Also please send me the integration document between ArcSight and Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 09:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ArcSight-and-Splunk/m-p/91433#M19011</guid>
      <dc:creator>rakeshmukherjee</dc:creator>
      <dc:date>2012-10-16T09:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: ArcSight and Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ArcSight-and-Splunk/m-p/91434#M19012</link>
      <description>&lt;P&gt;I think you've misunderstood the purpose of splunkbase. It is not a general forum for communicating requests to Splunk sales. It is a questions/answers sites where volunteers help out with issues and queries regarding designing, implementing and operating Splunk installations. As such, my suggestion is that you get in contact with Splunk sales.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 10:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ArcSight-and-Splunk/m-p/91434#M19012</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-16T10:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: ArcSight and Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ArcSight-and-Splunk/m-p/91435#M19013</link>
      <description>&lt;P&gt;Have a look at this document.  &lt;A href="http://www.splunk.com/web_assets/pdfs/resources/Integrating_Splunk_with_Arcsight.pdf" target="_blank"&gt;http://www.splunk.com/web_assets/pdfs/resources/Integrating_Splunk_with_Arcsight.pdf&lt;/A&gt;  While this provides the basics, I believe that more in depth work would be needed to properly map the Windows audit logs.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ArcSight-and-Splunk/m-p/91435#M19013</guid>
      <dc:creator>mlulmer</dc:creator>
      <dc:date>2020-09-28T14:42:01Z</dc:date>
    </item>
  </channel>
</rss>

