Dashboards & Visualizations

Arcsight to HEC

sahiltcs
Path Finder

We have two options to send  our Splunk Cloud, Please suggest which option is best .

1) HF outputs syslog to LogStash and logstash pushes to HEC.

arcsight -> HF -> logstash -> HEC

2. Arcsight pushes to Nifi and nifi transforms and pushes to HEC

arcsight -> Nifi -> HEC

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Why are those your only two options?  Arcsight can produce syslog output so you also have these options:

3. Arcsight -> HF -> Splunk Cloud

4. Arcsight -> Splunk Connect for Syslog (SC4S) -> HEC

I recommend option 4 because it's easy to manage and performs well.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...