Based on what I read it is possible to forward logs from ArcSight to McAfee SIEM using CEF. However, I think this is limited to the upcoming logs only.
Is there a way or does McAfee SIEM support the ingestion of the old events generated by the connectors/data sources of ArcSight?
Usually not. Importing old data into an SIEM is problematic due to aggregation. You could send them to the ELM and they would still be searchable though.
Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center
2821 Mission College Blvd.
Santa Clara, CA 95054 USA
Consumer Support | Enterprise Support | McAfee.com
Legal | Privacy | Copyright © 2019 McAfee, LLC