victormanuel1

Cadet 1st Class
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2020-12-14
10:48
216 views
It would be good practice, to have the same fields indexed in logger and ESM. With the evolution that ArcSight will this change?
1 Solution
Accepted Solutions
toor

Micro Focus Expert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2020-12-14
11:43
Yes, that will change as both products will be changed in the future in regards to how they store their events. Logger will be merged together with RECON which as of today already uses the new unified data lake solution underneath.
ESM as well will be changed in the way it stores data and be using the unified data lake in future versions. While we are seeing this as a fairly complex change to the heart of ESMs architecture, we still target July for that to happen (but this is ideal and might change).
1 Reply
toor

Micro Focus Expert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2020-12-14
11:43
Yes, that will change as both products will be changed in the future in regards to how they store their events. Logger will be merged together with RECON which as of today already uses the new unified data lake solution underneath.
ESM as well will be changed in the way it stores data and be using the unified data lake in future versions. While we are seeing this as a fairly complex change to the heart of ESMs architecture, we still target July for that to happen (but this is ideal and might change).