Linking RSA with Logstash etc
Posted
by
Anuj
on Server Fault
See other posts from Server Fault
or by Anuj
Published on 2012-04-03T09:11:11Z
Indexed on
2012/04/03
11:33 UTC
Read the original article
Hit count: 404
rsa
i was wondering whether we can use logstash or any other opn source or free Log management too to collect,index the data and then feed this index into RSA envision or any other enterprise SIEM tool. Will this be beneficial in any way? Also are the indexes of various Log Management and SIEM tools -- splunk,RSA envision,HP Arcsight Logger and Logstash etc compatiable with each other. My organization is planning to buy RSA envision appliance and is there any way to restrict or select only certian type of log files eg: security logs or apache logs .. so that onlt those are monitored and this will reduce the EPS(events per second).
© Server Fault or respective owner