Depends on the data and what you want to do, but most likely if you have the data in ArcSight, you can pull it directly into UBA without much fuss. ArcSight (assuming UBA gets the CEF output) will act as a normalization layer, and make life easy for UBA. Not familiar with an ArcSight SPAN sensor myself, but so I can't speak personally to ArcSight vs Bro, but Bro will extract connection and application data (e.g., HTTP requests, Emails, etc.) while listening on a SPAN port, at pretty high speeds. Splunk Stream also does similar things -- both tools have a few unique pieces of functionality that the other doesn't and make themselves better for some use cases, but share similar core functionality.
Notably, these are all things that Splunk engineers are happy to help answer -- if you're working on a deployment like this, maybe you reach out to your SE? If you don't know who your SE is, I can reach out offline to set up a conversation.
... View more