I am new Splunk. Earlier, we were using the Arcsight for the SOC operation. Now, we are migrating to Splunk. so could you please help me or guide me to migrate the environment from Arcsight to Splunk?
I am not at all an expert on Arcsight. But I think that some basic knowledge about Splunk will be very useful.
First, I would strongly suggest that you should take some Splunk training to get at least one member of your team educated as a Splunk administrator. [Caveat: I teach classes for Splunk. But I still feel strongly that your Splunk installation will be better in the short term and in the long term with at least one trained admin.]
AFAIK there are no prerequisites for migration. But I probably don't understand what you mean by migration. Are you planning to move data that has already been ingested into Arcsight? Do you have the original log files?
Splunk uses agents called forwarders to collect the data. The forwarders send the data via TCP to indexers. Each forwarder is configured for both inputs (data to be collected) and outputs (where to send the data). Splunk does not use connectors; no a priori knowledge of the input format is needed.
Splunk does not do log rotation. However, it does work properly even as logs are rotated. Most people use the logrotate utility on Linux, but you can use whatever you wish. If you compress older logs, you should move them to a different, unmonitored directory.
Take a look at the Getting Started page in the documentation. The Search Tutorial has a very brief introduction to bringing data into Splunk, but it is specific to the tutorial. The Getting Data In manual will show you exactly how to bring your data sources into Splunk.
Thanks for your reply. We are doing that only and but when you have some immediate task that time you can't read an entire story. Sometimes, you just need to have some inputs where you can put more focus and then later on you can complete your task. However, we are doing the self-paced training for our learning purpose along with that we are asking the question which is part of the training only.
I really appreciate for whatever suggestion and guidance you said and we will go with that.