DevOps Cloud
IT Operations Cloud
OpenText product name changes coming to the community soon! Learn more.
ArcSight SmartConnector -> Universal Common Event Format
*Most CEF events parse properly but as an ArcSight SME I needed a few more in Sentinel.
Two examples
- Cisco Firepower
- McAfee ePO
Get Raw Data
- Option 1: Sentinel webUI “Get Raw Data”
- Option 2: Go to Sentinel Control Center and right click on SyslogConnector to find an option “Edit” where they can copy raw data to a file.
Parser - CustomFieldMap