A few Panorama-questions

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

A few Panorama-questions

L6 Presenter

Hi all!

Got a few question related to Panorama which I hope you can help me with?

1) Whats the FR id regarding having Panorama to be able to forward received logs?

That is PA-device -> Panorama -> SEIM/Syslogarchive.

2) For which version is this feature expected to show up, and any ETA for when we will see this version available in the download section (that is version and date)?

3) If you log towards an ArcSight installation you can use the CEF-format in the PA-devices. However the CEF format has an overhead of approx 220 bytes (or so) per msg. Which gives that during a burst of say 100.000 msgs/sec the overhead is approx 176 Mbit/s on the line.

Do there exist a more efficient way of transmitting logs from PA to ArcSight other than CEF?

I mean did PA (or HP?) create a custom flexconnector or such to read native format of PA or is CEF the only available option unless I want to create a flexconnector on my own?

4) Speaking of CEF, any ETA (version and date) for when we will see panos version as a variable?

1 accepted solution

Accepted Solutions

L6 Presenter

Hi...The FR ID is 782.  If you have a customer who wants this feature, please submit the customer's name to your local SE and the SE can add to the FR.  This feature is coming soon.

For ArcSight, there was a FlexConnector developed several years ago and HP (ArcSight) is responsible for it.  You should check with HP to see if they still offer it. Otherwise, CEF format is supported as you have pointed out.

Thanks.

View solution in original post

1 REPLY 1

L6 Presenter

Hi...The FR ID is 782.  If you have a customer who wants this feature, please submit the customer's name to your local SE and the SE can add to the FR.  This feature is coming soon.

For ArcSight, there was a FlexConnector developed several years ago and HP (ArcSight) is responsible for it.  You should check with HP to see if they still offer it. Otherwise, CEF format is supported as you have pointed out.

Thanks.

  • 1 accepted solution
  • 1647 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!