<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPLUNK APP that preserves events in the same format as it receives them for integration purposes with ArcSight in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-APP-that-preserves-events-in-the-same-format-as-it/m-p/113777#M23823</link>
    <description>&lt;P&gt;Does the Splunk App for CEF convert the data to the same CEF format as ArcSight CEF?&lt;/P&gt;

&lt;P&gt;You mention that the SPLUNK app for CEF provides a continuous export of the data from SPLUNK which sounds good but the question I have on this is "Do you have to map every event one by one first or is there some way to just get a full export of the SPLUNK data all at once?"&lt;/P&gt;

&lt;P&gt;Can you shed some light on these problems for us? &lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Fri, 07 Nov 2014 15:17:29 GMT</pubDate>
    <dc:creator>jtsapos</dc:creator>
    <dc:date>2014-11-07T15:17:29Z</dc:date>
    <item>
      <title>SPLUNK APP that preserves events in the same format as it receives them for integration purposes with ArcSight</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-APP-that-preserves-events-in-the-same-format-as-it/m-p/113775#M23821</link>
      <description>&lt;P&gt;I got some info from an ArcSight engineer that Splunk recently brought out its own App that will preserve log data in the same format that it receives it and I am lead to believe that it does a lot of the processing to make sure that the data coming out of SPLUNK is in the same format that comes in from the different vendors. &lt;/P&gt;

&lt;P&gt;It should make it simpler to do and easier to manage, but at the moment I haven't had the chance to look at this and I can't comment directly. &lt;/P&gt;

&lt;P&gt;Maybe someone else has done this or knows more about this?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2014 17:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-APP-that-preserves-events-in-the-same-format-as-it/m-p/113775#M23821</guid>
      <dc:creator>jtsapos</dc:creator>
      <dc:date>2014-11-06T17:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK APP that preserves events in the same format as it receives them for integration purposes with ArcSight</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-APP-that-preserves-events-in-the-same-format-as-it/m-p/113776#M23822</link>
      <description>&lt;P&gt;You are likely referring to the &lt;A href="https://apps.splunk.com/app/1847/"&gt;Splunk App for CEF&lt;/A&gt;. It provides an user interface that helps set up a continuous export of data from Splunk to another device that accepts CEF (such as ArcSight).&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2014 06:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-APP-that-preserves-events-in-the-same-format-as-it/m-p/113776#M23822</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2014-11-07T06:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK APP that preserves events in the same format as it receives them for integration purposes with ArcSight</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-APP-that-preserves-events-in-the-same-format-as-it/m-p/113777#M23823</link>
      <description>&lt;P&gt;Does the Splunk App for CEF convert the data to the same CEF format as ArcSight CEF?&lt;/P&gt;

&lt;P&gt;You mention that the SPLUNK app for CEF provides a continuous export of the data from SPLUNK which sounds good but the question I have on this is "Do you have to map every event one by one first or is there some way to just get a full export of the SPLUNK data all at once?"&lt;/P&gt;

&lt;P&gt;Can you shed some light on these problems for us? &lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2014 15:17:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-APP-that-preserves-events-in-the-same-format-as-it/m-p/113777#M23823</guid>
      <dc:creator>jtsapos</dc:creator>
      <dc:date>2014-11-07T15:17:29Z</dc:date>
    </item>
  </channel>
</rss>

