Linking RSA with Logstash etc

Posted by Anuj on Server Fault See other posts from Server Fault or by Anuj
Published on 2012-04-03T09:11:11Z Indexed on 2012/04/03 11:33 UTC
Read the original article Hit count: 370

Filed under:

i was wondering whether we can use logstash or any other opn source or free Log management too to collect,index the data and then feed this index into RSA envision or any other enterprise SIEM tool. Will this be beneficial in any way? Also are the indexes of various Log Management and SIEM tools -- splunk,RSA envision,HP Arcsight Logger and Logstash etc compatiable with each other. My organization is planning to buy RSA envision appliance and is there any way to restrict or select only certian type of log files eg: security logs or apache logs .. so that onlt those are monitored and this will reduce the EPS(events per second).

© Server Fault or respective owner

Related posts about rsa