Getting Data In

Migrating Arcsight to Splunk

Steave4app
New Member

Hi Guys,

I am new Splunk. Earlier, we were using the Arcsight for the SOC operation. Now, we are migrating to Splunk. so could you please help me or guide me to migrate the environment from Arcsight to Splunk?

  1. What are the prerequisite for migration from Arcsight to Splunk?
  2. How the data sources can be configure to send the logs to Indexer?
  3. What would the default log rotation period?
Tags (1)
0 Karma

lguinn2
Legend

I am not at all an expert on Arcsight. But I think that some basic knowledge about Splunk will be very useful.

First, I would strongly suggest that you should take some Splunk training to get at least one member of your team educated as a Splunk administrator. [Caveat: I teach classes for Splunk. But I still feel strongly that your Splunk installation will be better in the short term and in the long term with at least one trained admin.]

  1. AFAIK there are no prerequisites for migration. But I probably don't understand what you mean by migration. Are you planning to move data that has already been ingested into Arcsight? Do you have the original log files?

  2. Splunk uses agents called forwarders to collect the data. The forwarders send the data via TCP to indexers. Each forwarder is configured for both inputs (data to be collected) and outputs (where to send the data). Splunk does not use connectors; no a priori knowledge of the input format is needed.

  3. Splunk does not do log rotation. However, it does work properly even as logs are rotated. Most people use the logrotate utility on Linux, but you can use whatever you wish. If you compress older logs, you should move them to a different, unmonitored directory.

Take a look at the Getting Started page in the documentation. The Search Tutorial has a very brief introduction to bringing data into Splunk, but it is specific to the tutorial. The Getting Data In manual will show you exactly how to bring your data sources into Splunk.

0 Karma

Steave4app
New Member

Hi Lgunin,

Thanks for your reply. We are doing that only and but when you have some immediate task that time you can't read an entire story. Sometimes, you just need to have some inputs where you can put more focus and then later on you can complete your task. However, we are doing the self-paced training for our learning purpose along with that we are asking the question which is part of the training only.

I really appreciate for whatever suggestion and guidance you said and we will go with that.

Thanks,
Steave

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...