<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security logs from EMC Celerra in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Security-logs-from-EMC-Celerra/m-p/196489#M98685</link>
    <description>&lt;P&gt;You should be able to use the Common Event Enabler (&lt;A href="http://emcsan.wordpress.com/2013/12/03/what-is-emcs-cava-common-event-enabler/"&gt;intro blog post&lt;/A&gt;), which is a piece of free middleware from EMC that gathers file events from VNX (probably Celerra, Internet says yes), and Isilon, and notifies subscribers of those events in a managed way. It's often used for antivirus products, but is also used for audit use cases.&lt;/P&gt;

&lt;P&gt;Long story short, watch this page ( &lt;A href="http://apps.splunk.com/apps/#/search/vnx"&gt;http://apps.splunk.com/apps/#/search/vnx&lt;/A&gt; ), an app should appear there shortly, it was submitted the other day.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Mar 2014 19:52:11 GMT</pubDate>
    <dc:creator>halr9000</dc:creator>
    <dc:date>2014-03-21T19:52:11Z</dc:date>
    <item>
      <title>Security logs from EMC Celerra</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Security-logs-from-EMC-Celerra/m-p/196488#M98684</link>
      <description>&lt;P&gt;Does anyone have experience reading security logs from an EMC Celerra?&lt;/P&gt;

&lt;P&gt;Our storage people are able to export a "live" file in an EVT format. However, Windows is unable to open it up. I can, however, use the "connect to computer" from a windows box to the datamover, and I can see the log. It just doesn't work from this export.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2014 15:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Security-logs-from-EMC-Celerra/m-p/196488#M98684</guid>
      <dc:creator>zafunt</dc:creator>
      <dc:date>2014-03-20T15:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Security logs from EMC Celerra</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Security-logs-from-EMC-Celerra/m-p/196489#M98685</link>
      <description>&lt;P&gt;You should be able to use the Common Event Enabler (&lt;A href="http://emcsan.wordpress.com/2013/12/03/what-is-emcs-cava-common-event-enabler/"&gt;intro blog post&lt;/A&gt;), which is a piece of free middleware from EMC that gathers file events from VNX (probably Celerra, Internet says yes), and Isilon, and notifies subscribers of those events in a managed way. It's often used for antivirus products, but is also used for audit use cases.&lt;/P&gt;

&lt;P&gt;Long story short, watch this page ( &lt;A href="http://apps.splunk.com/apps/#/search/vnx"&gt;http://apps.splunk.com/apps/#/search/vnx&lt;/A&gt; ), an app should appear there shortly, it was submitted the other day.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 19:52:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Security-logs-from-EMC-Celerra/m-p/196489#M98685</guid>
      <dc:creator>halr9000</dc:creator>
      <dc:date>2014-03-21T19:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Security logs from EMC Celerra</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Security-logs-from-EMC-Celerra/m-p/196490#M98686</link>
      <description>&lt;P&gt;Yep, I uploaded it yesterday, am an awaiting approval.  There will be 2 components, the add on that has communicates with EMC CEE API, and the app which contains all the lookup tables, field extractions, etc.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 22:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Security-logs-from-EMC-Celerra/m-p/196490#M98686</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2014-03-21T22:07:37Z</dc:date>
    </item>
  </channel>
</rss>

