Events within RSA enVision can output directly to a flat file by way of the “lsdata” command. Based on specific criteria passed with the lsdata command, events collected are presented in a syslog formatted log file.
Example: lsdata –events syslog –time start now >> log.unx
After that you can have these files be picked up by Splunk UF/HF and forward them to your Splunk index.
/D
... View more
lsdata is your friend, I managed to use it successfully to export Cisco ASA logs (intact), save them to a local file on the enVision appliance and then pull them from the Splunk server side via SMB file share. This involves batch jobs on both sides.
https://community.emc.com/thread/153234
... View more