Getting Data In

SPLUNK APP that preserves events in the same format as it receives them for integration purposes with ArcSight

jtsapos
Explorer

I got some info from an ArcSight engineer that Splunk recently brought out its own App that will preserve log data in the same format that it receives it and I am lead to believe that it does a lot of the processing to make sure that the data coming out of SPLUNK is in the same format that comes in from the different vendors.

It should make it simpler to do and easier to manage, but at the moment I haven't had the chance to look at this and I can't comment directly.

Maybe someone else has done this or knows more about this?

Thanks in advance.

0 Karma

jtsapos
Explorer

Does the Splunk App for CEF convert the data to the same CEF format as ArcSight CEF?

You mention that the SPLUNK app for CEF provides a continuous export of the data from SPLUNK which sounds good but the question I have on this is "Do you have to map every event one by one first or is there some way to just get a full export of the SPLUNK data all at once?"

Can you shed some light on these problems for us?

Thanks in advance

0 Karma

LukeMurphey
Champion

You are likely referring to the Splunk App for CEF. It provides an user interface that helps set up a continuous export of data from Splunk to another device that accepts CEF (such as ArcSight).

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...