09-30-2018 10:48 AM
hello,
is Cisco umbrella able to integrate with ArcSight for investigation?
I know that Cisco umbrella can intergrade with Splunk but what about ArcSight?
thanks
11-11-2018 03:36 AM
Hi,
Below doc explains the log management in Amazon S3/Splunk/Q-Radar. Couldn't find any doc for Arcsight. You can check with local cisco account manager for cisco umbrella support Arcsight.
https://support.umbrella.com/hc/en-us/articles/231248448-Cisco-Umbrella-Log-Management-in-Amazon-S3
HTH
Abheesh
11-24-2018 06:30 AM
You need to convert the json output into cef or something readable by arcsight. I did some reading in their forums and it looks like it can parse json with a little work on your part.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide