Hello , We are planning to injest data from arcsight logs to splunk. So we need to convert the data to splunk in readable format. So what is the procedure ?
Short answer: if it's text then Splunk can read it.
Splunk does not read non-text data so there is no set procedure for doing so. There are several apps available at apps.splunk.com for ingesting ArcSight data. Perhaps one of them will help you.