Dashboards & Visualizations

Arcsight to HEC

sahiltcs
Path Finder

We have two options to send  our Splunk Cloud, Please suggest which option is best .

1) HF outputs syslog to LogStash and logstash pushes to HEC.

arcsight -> HF -> logstash -> HEC

2. Arcsight pushes to Nifi and nifi transforms and pushes to HEC

arcsight -> Nifi -> HEC

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Why are those your only two options?  Arcsight can produce syslog output so you also have these options:

3. Arcsight -> HF -> Splunk Cloud

4. Arcsight -> Splunk Connect for Syslog (SC4S) -> HEC

I recommend option 4 because it's easy to manage and performs well.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...