The integrating Splunk with Arcsight document, states it is possible to feed Splunk with data coming straight from a Connector. Do you have any idea how this is possible?
The ArcSight website is not as full of infos as Splunk's...
And, yes, I know this might not be the right community, but it's the one I happen to trust.
Paolo
If you meant how to configure the arcsight agent to send the data out to splunk , let me know and I'll send you instructions on how to ...
run the command ..installdir\current\bin\arcsight agentsetup
choose yes to start the wizardmode
choose I want to add/remove/modify arcsight Manager destinations
choose add new destination
choose raw syslog
add the information of the splunk input you prepared choose the protocol.
hope this helps.
Hey gooza, could you send me the instructions for me to have a look? Appreciate!
Hi gooza, Please help me out how to configure arcsight agent to send data to splunk.
I'd also like the instructions please.
Hello. If you still have the configuration on setting up Splunk to receive data from Connectors that'll be awesome! Can you send me a copy of your instructions? Thanks.
Just wondering: is it possible to forward CEF data to splunk from Logger itself to Splunk? This would limit the effort on the connectors as, I'm told, you need quite a number of them even for small environments
Yes , I sent you the instructions how,
Gooza,
Could you send me the instructions also please?
Hi gooza. So, it is possible to configure an Arcsight Connector to send data to a 3rd party receiver in CEF over Syslog format. Thank you very much
Hi, thanks for the reply. Yes, I meant how to configure the Connectors.
I highly recommend using http://splunk-base.splunk.com/apps/22280/cef-common-event-format-extraction-utilities
it parse the arcsight cef format quit easily
as for time stamps extractions I recommend adding the following in the relevent stanza in porps.conf:
TIME_PREFIX = \s(end|rt)\=
TIME_FORMAT = %10S%3n
MAX_TIMESTAMP_LOOKHEAD = 350