cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1641
Views
0
Helpful
2
Replies

cisco umbrella and arcsight

safwat.ghazy
Level 1
Level 1

hello,

is Cisco umbrella able to integrate with ArcSight for investigation?

 

I know that Cisco umbrella can intergrade with Splunk but what about ArcSight?

 

 

thanks

 

2 Replies 2

Abheesh Kumar
VIP Alumni
VIP Alumni

Hi,

Below doc explains the log management in Amazon S3/Splunk/Q-Radar. Couldn't find any doc for Arcsight. You can check with local cisco account manager for cisco umbrella support Arcsight.

https://support.umbrella.com/hc/en-us/articles/231248448-Cisco-Umbrella-Log-Management-in-Amazon-S3

 

HTH

Abheesh

babiojd01
Level 1
Level 1

You need to convert the json output into cef or something readable by arcsight. I did some reading in their forums and it looks like it can parse json with a little work on your part.