Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Event log back up / Retrieval from ArcSight Logger appliance

Posted on 2013-12-03
4
Medium Priority
?
1,597 Views
Last Modified: 2013-12-09
I would like to know if it's possible to retrieve event logs from an old ArcSight Logger?   I read that by default, the ArcSight Logger does not back up any content but will back up 'All non-event data' and 'Report content' which includes:

• System Information
• Logs
• Global Settings
• User and Group Information
• All Configuration Settings
• Existing Filters and Saved Searches
• Logger Monitor settings
The following Reports content:
• Queries, Reports, Parameters,
Parameter Value Groups, Dashboard
• Templates

I am looking to extract this information if possible to prepare for an upcoming inspection.  Any information would greatly appreciated.

Cheers,
Larry
0
Comment
Question by:holby
  • 3
4 Comments
 
LVL 29

Accepted Solution

by:
fibo earned 2000 total points
ID: 39696311
Not sure I understand: are you looking for the place where these logs would be?
- usually /var/log is a good place to start
- you can also hunt at /etc/logrotate.d which handles nicely some logs (but be careful here!)

As usual
locate *.log
is your best friend (but do not forget
updatedb
)
0
 

Author Comment

by:holby
ID: 39696378
Yes I am looking for the location on the logger where these event logs are stored by default.  We moved away from ArcSight because it was a very convoluted product and extremely difficult to learn unless you were an expert using Unix.  We have since moved to a McAfee Nitro Security appliance and this product is much nicer and is less cumbersome.  Just need to be able to extract the event logs off the logger in case we need to present them for our upcoming inspection.
0
 
LVL 29

Expert Comment

by:fibo
ID: 39697645
What gives locate *.log?
0
 
LVL 29

Expert Comment

by:fibo
ID: 39706700
B-) Glad I could help. Thx for the grade and points
Bernard
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Your data is at risk. Probably more today that at any other time in history. There are simply more people with more access to the Web with bad intentions.
In this article, I’ll look at how you can use a backup to start a secondary instance for MongoDB.
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
Suggested Courses

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question