<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NetApp, event logs and SIEM - ArcSight in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76461#M6928</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The NetApp administrator and I got this to work - mostly configuration requirements on the NetApp end.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Oct 2011 18:47:15 GMT</pubDate>
    <dc:creator>chopisnetapp</dc:creator>
    <dc:date>2011-10-06T18:47:15Z</dc:date>
    <item>
      <title>NetApp, event logs and SIEM - ArcSight</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76451#M6926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am writing to inquire if anyone has experience with sending audit-file information to a Security Incident and Event Manager (SIEM) like ArcSight.&lt;/P&gt;&lt;P&gt;I am particularly interested in MS file access logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:49:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76451#M6926</guid>
      <dc:creator>chopisnetapp</dc:creator>
      <dc:date>2025-06-05T06:49:04Z</dc:date>
    </item>
    <item>
      <title>NetApp, event logs and SIEM - ArcSight</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76456#M6927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If ArcSight cannot do this natively, then you need Adiscon EventReporter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2011 20:11:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76456#M6927</guid>
      <dc:creator>txskibum2000</dc:creator>
      <dc:date>2011-08-01T20:11:44Z</dc:date>
    </item>
    <item>
      <title>NetApp, event logs and SIEM - ArcSight</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76461#M6928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The NetApp administrator and I got this to work - mostly configuration requirements on the NetApp end.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 18:47:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76461#M6928</guid>
      <dc:creator>chopisnetapp</dc:creator>
      <dc:date>2011-10-06T18:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp, event logs and SIEM - ArcSight</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76464#M6929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you describe what the NetApp admin had to do ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 01:42:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76464#M6929</guid>
      <dc:creator>NETAPPAIRTRAN</dc:creator>
      <dc:date>2012-01-27T01:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: NetApp, event logs and SIEM - ArcSight</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76468#M6930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We finally went with LogRythm for event log and cifs log reporting.&amp;nbsp; Does this nicely without an agent, etc.&lt;/P&gt;&lt;P&gt;However, nothing I can find can do Real Time File Intergrity Monitoring (FIM) without doing away with NetApp CIFS and migrating the file shares from the NetApp to a Windows front-end Server.&lt;/P&gt;&lt;P&gt;Here is some info on File Integrity Monitoring (FIM):&lt;/P&gt;&lt;P&gt;1. Alerts on any file or folder additions, deletions, modifications, or reads.&lt;/P&gt;&lt;P&gt;2. Can alert on a variety of malicious behaviors, from improper user access of confidential files to botnet related breaches and transmittal of sensitive data.&lt;/P&gt;&lt;P&gt;3. Meets PCI DSS compliance for sections 11.5* and 12.9 – specifically addresses 35 specific mandates of PCI DSS 1.2.&lt;/P&gt;&lt;P&gt;4. Provides a complete set of forensic data for rapidly identifying the root cause of security breaches.&lt;/P&gt;&lt;P&gt;*11.5 mandates that we deploy file integrity monitoring to alert personnel to unauthorized modifications of critical system or content files, and perform file comparisons at least weekly or more frequently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My two cents.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jan 2012 16:33:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/NetApp-event-logs-and-SIEM-ArcSight/m-p/76468#M6930</guid>
      <dc:creator>txskibum2000</dc:creator>
      <dc:date>2012-01-30T16:33:49Z</dc:date>
    </item>
  </channel>
</rss>

