Getting Data In

Security logs from EMC Celerra

zafunt
Explorer

Does anyone have experience reading security logs from an EMC Celerra?

Our storage people are able to export a "live" file in an EVT format. However, Windows is unable to open it up. I can, however, use the "connect to computer" from a windows box to the datamover, and I can see the log. It just doesn't work from this export.

Tags (3)

halr9000
Motivator

You should be able to use the Common Event Enabler (intro blog post), which is a piece of free middleware from EMC that gathers file events from VNX (probably Celerra, Internet says yes), and Isilon, and notifies subscribers of those events in a managed way. It's often used for antivirus products, but is also used for audit use cases.

Long story short, watch this page ( http://apps.splunk.com/apps/#/search/vnx ), an app should appear there shortly, it was submitted the other day.

dmaislin_splunk
Splunk Employee
Splunk Employee

Yep, I uploaded it yesterday, am an awaiting approval. There will be 2 components, the add on that has communicates with EMC CEE API, and the app which contains all the lookup tables, field extractions, etc.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...