<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using an existing OSSEC app with ES in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Using-an-existing-OSSEC-app-with-ES/m-p/185711#M916</link>
    <description>&lt;P&gt;The OSSEC is installed in a 6.0.x server that is not a part of the ES deployment.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2013 18:21:27 GMT</pubDate>
    <dc:creator>lprine</dc:creator>
    <dc:date>2013-12-19T18:21:27Z</dc:date>
    <item>
      <title>Using an existing OSSEC app with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Using-an-existing-OSSEC-app-with-ES/m-p/185709#M914</link>
      <description>&lt;P&gt;I have a working install of "Reporting and Management for OSSEC" working nicely now. Now that we have purchased ES and want to start deploying it, I'm a little lost on how if its even possible to use the existing OSSEC install with ES.&lt;/P&gt;

&lt;P&gt;Can I just make the existing Reporting and Management for OSSEC a heavy forwarder to ES and classify the data as ossec on the ES server?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 17:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Using-an-existing-OSSEC-app-with-ES/m-p/185709#M914</guid>
      <dc:creator>lprine</dc:creator>
      <dc:date>2013-12-19T17:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Using an existing OSSEC app with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Using-an-existing-OSSEC-app-with-ES/m-p/185710#M915</link>
      <description>&lt;P&gt;Hi, OSSEC has a lot of data, and we don't want to generate duplicates from other sources (e.g. login events). There's a TA in ES that will parse the OSSEC data for change management events. To use it, you just need to let your ES search head search the index where OSSEC data is written (Manager &amp;gt; Roles &amp;gt; Admin &amp;gt; Indexes searched by default). You may need to tweak the sourcetype in TA-ossec's props.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 18:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Using-an-existing-OSSEC-app-with-ES/m-p/185710#M915</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2013-12-19T18:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using an existing OSSEC app with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Using-an-existing-OSSEC-app-with-ES/m-p/185711#M916</link>
      <description>&lt;P&gt;The OSSEC is installed in a 6.0.x server that is not a part of the ES deployment.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 18:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Using-an-existing-OSSEC-app-with-ES/m-p/185711#M916</guid>
      <dc:creator>lprine</dc:creator>
      <dc:date>2013-12-19T18:21:27Z</dc:date>
    </item>
  </channel>
</rss>

