So our current setup in 10.x is a pair of ESMs (in redundant) and a Combo box enrolled as a child ESM. Now were thinking of upgrading to 11.x which doesnt support distributed setup anymore, do you guys have any idea how we might integrate the combo box to our siem system. Ive thought of enrolling it as part of the ESM cluster but the problem with that is, how would I collect the data from the Combo box to join the main data pool. I also thought of making the Combo box the management node and just re-enroll the existing receiver to the combo box but that would require major infra changes, not to mention that the combo box is gen 4 and is at our DR site. Appreciate any help I can get, thanks
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.