cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

SIEM 9.6 to 11.x upgrade

Good day,

We have a plan to do upgrade our old SIEM 9.6 (ESM, ERC, ACE and ELM VMs) to 11.x.

What is the best way to do it:

1) Try to perform upgrade procedures on existing system via 9.6 - 10.0 - 11.x or

2) Deploy new fresh SIEM 11.x system and then export rules, alarms, WLs and so on from SIEM 9.6 and import them into SIEM 11

 

 

 

4 Replies
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 5

Re: SIEM 9.6 to 11.x upgrade

If there's no data inside the 9.6 SIEM that you need, you have a pretty great opportunity that does not come up that often, which is to ensure everything is normalized inside the new environment and make sure any legacy rules, devices, etc... are cleaned out.

Depending on how big your device tree is, and if you need the residual data would be the primary determining factors on how to procede.

Brent
Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 3 of 5

Re: SIEM 9.6 to 11.x upgrade

really depends on your situation:

- if you got events and config to keep > upgrade as per recommended path

- if you ain't got anything to keep > reimage device straight to newest version

Also, if you are working with physical appliances, remember you have to reimage via DVD and configure network settings via physical monitor and keyboard, etc.

Highlighted

Re: SIEM 9.6 to 11.x upgrade

Thanks for reply.

We use Virtual Applicances and would like to keep Correlation rules, alerts and Watch lists. So is it possible to export rules  from 9.6 and import it to 11.x  ?

 

Highlighted
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 5 of 5

Re: SIEM 9.6 to 11.x upgrade

You can export any custom rules using the policy editor. (Parser, and correlation) Watchlists are also exportable. However I am not sure you can export alarms.

Brent
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community