<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrate with RSA Archer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150908#M30693</link>
    <description>&lt;P&gt;I am unable to view the integration document also, I receive a restricted message.  Can we get an updated location or make the document accessible?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2017 16:13:59 GMT</pubDate>
    <dc:creator>michael_daoust</dc:creator>
    <dc:date>2017-07-21T16:13:59Z</dc:date>
    <item>
      <title>How do I send events from SPLUNK to be sent to RSA archer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150902#M30687</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;I am looking so send events from SPLUNK to be sent to RSA archer. does anyone have an idea what the best way to do it would be?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 15:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150902#M30687</guid>
      <dc:creator>ofernandes</dc:creator>
      <dc:date>2022-04-01T15:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150903#M30688</link>
      <description>&lt;P&gt;This really becomes a programming question because both tools have a web API, so you just need to be able to interface with them.  Splunk uses a REST API but has a good development kit to make things easier, and Archer uses a SOAP API.&lt;/P&gt;

&lt;P&gt;A good place to start is the Splunk SDK:&lt;BR /&gt;
&lt;A href="http://dev.splunk.com/view/sdks/SP-CAAADP7"&gt;http://dev.splunk.com/view/sdks/SP-CAAADP7&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And here is the Archer documentation:&lt;BR /&gt;
&lt;A href="https://community.emc.com/community/connect/grc_ecosystem/rsa_archer"&gt;https://community.emc.com/community/connect/grc_ecosystem/rsa_archer&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Adding records to Archer is slightly more complicated than pulling them out of Splunk, but essentially you just create a session token (general.CreateUserSessionFromInstance) and then add a record (record.CreateRecord) with your fields.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2014 16:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150903#M30688</guid>
      <dc:creator>pylanch</dc:creator>
      <dc:date>2014-09-16T16:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150904#M30689</link>
      <description>&lt;P&gt;Now Integration between Splunk and RSA Archer is available.  You can make use of the RSA Security Operations Solutions solution to integrate Splunk and RSA Archer.&lt;/P&gt;

&lt;P&gt;Records will be created in the Security Incidents, Security alerts application in RSA Archer.&lt;/P&gt;

&lt;P&gt;RSA Archer Security Operations Management helps you do the following:&lt;BR /&gt;
a&amp;gt;Prioritize and respond faster to security incidents by leveraging business context and actionable threat intelligence.&lt;BR /&gt;
b&amp;gt;Engage key business and IT stakeholders in the incident management process&lt;BR /&gt;
c&amp;gt;Simplify incident investigation and breach response procedures through industry best practice methodologies and response procedures.&lt;BR /&gt;
d&amp;gt;Optimize SOC investments through SOC KPI (key performance indicators)monitoring and staff time management tracking.&lt;/P&gt;

&lt;P&gt;Also customers can make use of the Devices application present in the Enterprise management solution to add more business context for the devices, mention the criticality of the device, link the device to the Business Unit and have full fledged enterprise solution integrated with RSA SecOps solution. &lt;/P&gt;

&lt;P&gt;More information about the integration can be found in the following link: &lt;BR /&gt;
&lt;A href="https://community.emc.com/docs/DOC-36270"&gt;https://community.emc.com/docs/DOC-36270&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;To know more about RSA Security Operations Management solution refer to the following link:&lt;BR /&gt;
&lt;A href="https://community.emc.com/docs/DOC-39988"&gt;https://community.emc.com/docs/DOC-39988&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Nithin Shubhananda&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 15:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150904#M30689</guid>
      <dc:creator>nithin_shubhana</dc:creator>
      <dc:date>2015-05-15T15:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150905#M30690</link>
      <description>&lt;P&gt;Hello Nithin,&lt;/P&gt;

&lt;P&gt;Thank you for sharing the information.&lt;BR /&gt;
However, the link is not available now.&lt;BR /&gt;
Could you please update the link? This subject is very intresting for us as a client of Archer.&lt;BR /&gt;
Thank you very much.&lt;/P&gt;

&lt;P&gt;Daiyu&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 16:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150905#M30690</guid>
      <dc:creator>Lindaiyu</dc:creator>
      <dc:date>2016-09-12T16:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150906#M30691</link>
      <description>&lt;P&gt;&lt;A href="https://community.emc.com/docs/DOC-36270"&gt;https://community.emc.com/docs/DOC-36270&lt;/A&gt; This link is restricted. any chance you can grant access ?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 21:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150906#M30691</guid>
      <dc:creator>danglim</dc:creator>
      <dc:date>2016-12-27T21:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150907#M30692</link>
      <description>&lt;P&gt;Did you get the document? Is it possible to share?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 18:05:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150907#M30692</guid>
      <dc:creator>monteirolopes</dc:creator>
      <dc:date>2017-07-06T18:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150908#M30693</link>
      <description>&lt;P&gt;I am unable to view the integration document also, I receive a restricted message.  Can we get an updated location or make the document accessible?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 16:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150908#M30693</guid>
      <dc:creator>michael_daoust</dc:creator>
      <dc:date>2017-07-21T16:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150909#M30694</link>
      <description>&lt;P&gt;Here are some updated links:&lt;/P&gt;

&lt;P&gt;Updated Links:&lt;/P&gt;

&lt;P&gt;Splunk Technology Integration to RSA Netwitness (Security Analytics) (Event Source Configuration) (which then integrates to RSA Archer Security Operations &amp;amp; Breach Management): &lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-76132"&gt;https://community.rsa.com/docs/DOC-76132&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;RSA Netwitness Integration to RSA Archer (with Unified Collector Framework UCF):&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-80978"&gt;https://community.rsa.com/docs/DOC-80978&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-81705"&gt;https://community.rsa.com/docs/DOC-81705&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-43085"&gt;https://community.rsa.com/docs/DOC-43085&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-74023"&gt;https://community.rsa.com/docs/DOC-74023&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;RSA Archer Use-Cases Documentations:&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-40093"&gt;https://community.rsa.com/docs/DOC-40093&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;RSA Archer Security Operations &amp;amp; Breach Management Use-Case:&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-32889"&gt;https://community.rsa.com/docs/DOC-32889&lt;/A&gt;  (english)&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-54512"&gt;https://community.rsa.com/docs/DOC-54512&lt;/A&gt;  (german)&lt;/P&gt;

&lt;P&gt;RSA Archer Community:&lt;BR /&gt;
&lt;A href="https://community.rsa.com/community/products/archer-grc"&gt;https://community.rsa.com/community/products/archer-grc&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;RSA Archer Documentation &amp;amp; Downloads:&lt;BR /&gt;
&lt;A href="https://community.rsa.com/community/products/archer-grc/exchange/documentation-downloads"&gt;https://community.rsa.com/community/products/archer-grc/exchange/documentation-downloads&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://community.rsa.com/community/products/archer-grc/archer-customer-partner-community/platform/63"&gt;https://community.rsa.com/community/products/archer-grc/archer-customer-partner-community/platform/63&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;RSA Archer Community News Update:&lt;BR /&gt;
&lt;A href="https://community.rsa.com/docs/DOC-22846"&gt;https://community.rsa.com/docs/DOC-22846&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 15:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150909#M30694</guid>
      <dc:creator>volkerstrecke</dc:creator>
      <dc:date>2018-01-24T15:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150910#M30695</link>
      <description>&lt;P&gt;These are just random docs that really does not answer the question asked. &lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 21:19:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/150910#M30695</guid>
      <dc:creator>alohsleoj</dc:creator>
      <dc:date>2019-06-17T21:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with RSA Archer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/591942#M103632</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;Administrators can integrate RSA NetWitness Suite with RSA NetWitness Security Operations (SecOps) Manager to send alerts and incidents from NetWitness Suite to Archer for incident management and remediation. This guide provides a high-level workflow for configuring this integration.&lt;/P&gt;&lt;P&gt;System integration brings different programs together to work smoothly without interfering with each other or demanding duplicate actions from the users so that data can flow seamlessly and uninterruptedly. For more information about Integration with RSA Archer.&lt;/P&gt;&lt;P&gt;Click here: &lt;A href="https://tekslate.com/rsa-archer-training" target="_self"&gt;RSA Archer Training&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I hope it solves your issue.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 13:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-events-from-SPLUNK-to-be-sent-to-RSA-archer/m-p/591942#M103632</guid>
      <dc:creator>david09</dc:creator>
      <dc:date>2022-04-01T13:14:39Z</dc:date>
    </item>
  </channel>
</rss>

