AnsweredAssumed Answered

How to forward the row logs from RSA SA Netwitness SIEM to Logrhythm?

Question asked by Utsav Sejpal on Jun 7, 2017
Latest reply on Jun 21, 2017 by Arthur Costigan

Hi Folks,


We have below architecture flow for RSA SA SIEM logging.

 

End device >> VLC >> Log Hybrid >> Archiver >> ESA >> SA


We wanted to forward the row logs of the end devices (which comes to RSA SIEM) to Logrhythm SIEM.

 

While some of the end devices do have the option to enable syslog for multiple destinations but not all of them. 

 

I referred below documents but not really sure if it serves the requirement. 

 

https://community.rsa.com/docs/DOC-64141

 

It says that logs of "syslog devices" can be forwarded from Log decoder to the other Syslog server. But what about the other event sources like windows, DBs etc.

 

Any suggestion/help around this would be much appreciated  

 

Thanks,

Utsav Sejpal

Outcomes