Splunk Dev

Arcsight 2 Splunk Transition

SamHTexas
Builder

Looking for new resources to transition from ArcSight to Splunk please. The resources found on Micro Focus site are very old. Links & docs are much appreciated. If you have done this before any Do's & Don't are welcomed. Thank u

Labels (1)
0 Karma

SamHTexas
Builder

I appreciate your response & Thank you for your time. I have a couple of questions 

What role does the Splunk Ent. Security app has with such transition?

Would you elaborate on mapping Arcsight rules to Splunk searches a bit & where such instructions are found.

Thanks again

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Enterprise Security is Splunk's SIEM product.  It is the replacement for ArcSight.

I'm not aware of any instructions for mapping ArcSight rules to Splunk searches.  It's probably a tedious manual process of looking at each ArcSight rule and then looking at each Splunk search to see which is a good match.  If a match is not found then write an equivalent Splunk search.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

Splunk has an entire Professional Services practice for this so it's not something that is easily summarized in a forum posting.  That's also why documentation is hard to come by.

You'll want the Splunk Enterprise Security app.  It's a premium product (extra cost), but is what Splunk offers as a SIEM.  Replacing ArcSight with core Splunk is likely to lead to disappointing results.

The first step in the transition is to install Splunk and start sending your data to it.  You should be able to send the data to both ArcSight and Splunk simultaneously.

Next, you'll need to map your ArcSight rules to Splunk searches.  Run the searches and compare the results to those reached by ArcSight.  Adjust the searches until you get the desired results.

Use ArcSight and Splunk side-by-side for a while to confirm Splunk is acting as expected.  Once you're confident in it, shut down ArcSight.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...