2015-07-15 05:59 AM
2015-07-16 12:41 AM
Hi Everyone,
Thanks a lot for your quick response, let me add parser for ESA and SA itself then i will update here.
2015-07-15 08:48 AM
Security Analytics doesnt fully support feeding ESA intelligence (output) towards SA. You would need to get a hold of support or a RSA rep to get this integrated. Last I heard there was some backend process to feed via syslog ESA to SA, in which you would need to individually enable syslog notification in each rule to feed syslog to SA. Not entirely sure if RSA supported a parser for this either.
2015-07-15 09:56 AM
That's how we've gotten around it. Use syslogs from the ESA rule and feed it back into SA. I had heard in future versions ESA was going to have their own dashboards.
2015-07-15 03:48 PM
Look for the SA Parser in this site, and the create your own dashboard based on the info you got from these parser.
2015-07-16 12:41 AM
Hi Everyone,
Thanks a lot for your quick response, let me add parser for ESA and SA itself then i will update here.