<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding splunk'd logs to third party siem  - McAfee ESM in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104550#M9547</link>
    <description>&lt;P&gt;I configured the outputs.conf in my etc/local dir to forward AD logs from an indexer to a 3rd part SIEM .  restarted, and still no joy.  any ideas.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2015 15:02:00 GMT</pubDate>
    <dc:creator>mariogiovannitt</dc:creator>
    <dc:date>2015-12-01T15:02:00Z</dc:date>
    <item>
      <title>Forwarding splunk'd logs to third party siem  - McAfee ESM</title>
      <link>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104546#M9543</link>
      <description>&lt;P&gt;I am told it is very simple to take already indexed events from splunk and send them over to a 3rd party SIEM appliance like McAfee ESM.   &lt;/P&gt;

&lt;P&gt;Has anyone done this successfully?   How hard was it to implement?  Can you limit / forward only selected events?  Can you limit forwarding to only select hosts or log types?  &lt;/P&gt;

&lt;P&gt;I have seen a few other similar questions and it seems INCREDIBLY simple, to the point of adding only a few lines of code to a few files.  Is it really that easy?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2013 22:36:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104546#M9543</guid>
      <dc:creator>MattQ</dc:creator>
      <dc:date>2013-07-23T22:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding splunk'd logs to third party siem  - McAfee ESM</title>
      <link>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104547#M9544</link>
      <description>&lt;P&gt;Use the REST or other API or the CLI to perform a search (scheduled or even real-time) and have the results sent to whatever API or file the other tool uses.&lt;/P&gt;

&lt;P&gt;It's relatively simple, really, and you can do this with any search you want so you can send selective results to your other tool.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2013 04:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104547#M9544</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2013-07-25T04:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding splunk'd logs to third party siem  - McAfee ESM</title>
      <link>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104548#M9545</link>
      <description>&lt;P&gt;You may also want to look at the Real-Time output app:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/apps/48082/splunk-real-time-output"&gt;http://splunk-base.splunk.com/apps/48082/splunk-real-time-output&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2013 12:54:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104548#M9545</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2013-07-25T12:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding splunk'd logs to third party siem  - McAfee ESM</title>
      <link>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104549#M9546</link>
      <description>&lt;P&gt;You could also use a heavy forwarder and forward the data to McAfee via syslog at the same time as it sends it to your Splunk indexer.  Of course this is before the data is indexed. This will also give you the flexibility to send a subset of the data.  See the docs below:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2013 13:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104549#M9546</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-07-25T13:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding splunk'd logs to third party siem  - McAfee ESM</title>
      <link>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104550#M9547</link>
      <description>&lt;P&gt;I configured the outputs.conf in my etc/local dir to forward AD logs from an indexer to a 3rd part SIEM .  restarted, and still no joy.  any ideas.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 15:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104550#M9547</guid>
      <dc:creator>mariogiovannitt</dc:creator>
      <dc:date>2015-12-01T15:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding splunk'd logs to third party siem  - McAfee ESM</title>
      <link>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104551#M9548</link>
      <description>&lt;P&gt;please refer any link or document.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 12:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Forwarding-splunk-d-logs-to-third-party-siem-McAfee-ESM/m-p/104551#M9548</guid>
      <dc:creator>kupawar</dc:creator>
      <dc:date>2017-05-17T12:15:53Z</dc:date>
    </item>
  </channel>
</rss>

