is it possible to integrate RSA envision SIEM log with McAfee SIEM ? if yes, how to do that.
In our client place they are using RSA envision SIEM now they want to evaluate McAfee SIEM, they are looking for option to forward raw logs from RSA envision to McAfee SIEM. Any one has done this before? Please help me with some ideas.
I haven't setup enVision to forward to McAfee however I have setup enVision to do a syslog forward to a syslogNG server. I expect the configuration would be the same; you probably want to use the original source ip address so you can differentiate the log sources.