- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi,
I am wondering if it is possible to sent data from Splunk UBA to Arcsight. I have found add-on integrate it with Enterprise Security and it seems they are communicating via RestAPI. Is there any workaround for sending UBA events (anomaly detection,etc.) to Arcsight?
Thanks and Best Regard,
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

While it's not officially supported (mostly: we reserve the right to change the fields as we move forward), you can configure UBA to output threats in syslog format, and then build a connector in ArcSight to deal with that. UBA can also send emails. This approach works well assuming that you have a Splunk (or Splunk-like capability) as well in your environment to handle data aggregation and a deep analyst investigation. If you only have ArcSight and are dipping your toes into a UEBA capability, I would recommend reaching out to Splunk Sales to get more information and guidance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

While it's not officially supported (mostly: we reserve the right to change the fields as we move forward), you can configure UBA to output threats in syslog format, and then build a connector in ArcSight to deal with that. UBA can also send emails. This approach works well assuming that you have a Splunk (or Splunk-like capability) as well in your environment to handle data aggregation and a deep analyst investigation. If you only have ArcSight and are dipping your toes into a UEBA capability, I would recommend reaching out to Splunk Sales to get more information and guidance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi David,
Many thanks for your answer. Capability of sending UBA events in syslog format will totally meet our needs.
Thanks and Best Regards,
Cem
