Solved

Event log back up / Retrieval from ArcSight Logger appliance

Posted on 2013-12-03
4
1,300 Views
Last Modified: 2013-12-09
I would like to know if it's possible to retrieve event logs from an old ArcSight Logger?   I read that by default, the ArcSight Logger does not back up any content but will back up 'All non-event data' and 'Report content' which includes:

• System Information
• Logs
• Global Settings
• User and Group Information
• All Configuration Settings
• Existing Filters and Saved Searches
• Logger Monitor settings
The following Reports content:
• Queries, Reports, Parameters,
Parameter Value Groups, Dashboard
• Templates

I am looking to extract this information if possible to prepare for an upcoming inspection.  Any information would greatly appreciated.

Cheers,
Larry
0
Comment
Question by:holby
  • 3
4 Comments
 
LVL 29

Accepted Solution

by:
fibo earned 500 total points
Comment Utility
Not sure I understand: are you looking for the place where these logs would be?
- usually /var/log is a good place to start
- you can also hunt at /etc/logrotate.d which handles nicely some logs (but be careful here!)

As usual
locate *.log
is your best friend (but do not forget
updatedb
)
0
 

Author Comment

by:holby
Comment Utility
Yes I am looking for the location on the logger where these event logs are stored by default.  We moved away from ArcSight because it was a very convoluted product and extremely difficult to learn unless you were an expert using Unix.  We have since moved to a McAfee Nitro Security appliance and this product is much nicer and is less cumbersome.  Just need to be able to extract the event logs off the logger in case we need to present them for our upcoming inspection.
0
 
LVL 29

Expert Comment

by:fibo
Comment Utility
What gives locate *.log?
0
 
LVL 29

Expert Comment

by:fibo
Comment Utility
B-) Glad I could help. Thx for the grade and points
Bernard
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

FreeBSD on EC2 FreeBSD (https://www.freebsd.org) is a robust Unix-like operating system that has been around for many years. FreeBSD is available on Amazon EC2 through Amazon Machine Images (AMIs) provided by FreeBSD developer and security office…
APEX (Application Express) is used to develop a web application from Oracle. SQL Workshop is one of the tools that comes with Oracle APEX to query or modify the database objects or to make any changes to the structure.
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Video by: Steve
Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now