Skip to main content
Solved

Usecases for Arista switch for Chronicle SIEM

  • March 6, 2024
  • 6 replies
  • 6 views

Forum|alt.badge.img+7

Does anyone know 5 different use cases for arista switch for chronicle SIEM

Best answer by dnehoda

Hello, 

I cannot think of 5 but, I can get you started with 3.

1.) Logging of access to the device 

2.) Port security - 802.1x changes 

3.) configuration changes

6 replies

dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • Answer
  • March 15, 2024

Hello, 

I cannot think of 5 but, I can get you started with 3.

1.) Logging of access to the device 

2.) Port security - 802.1x changes 

3.) configuration changes


Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • March 20, 2024

Hello, 

I cannot think of 5 but, I can get you started with 3.

1.) Logging of access to the device 

2.) Port security - 802.1x changes 

3.) configuration changes


Hi ,

Can you help me in writing the usecase for the one you mentioned above. Would greatly appreciate it.


dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • March 20, 2024

I'm sorry but I dont understand your question here? 

What does write the usecase mean?  


Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • March 21, 2024

I'm sorry but I dont understand your question here? 

What does write the usecase mean?  


I mean can you please help me with one example for the above usecase!


dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • March 21, 2024

I mean can you please help me with one example for the above usecase!


If the data is already being sent Chronicle, you would just need to do a
search for the appropriate fields.

If it’s not, you will most likely need to setup a forwarder or use the
ingestion api to get that data into Chronicle.

If you have not done that yet, please open a ticket with our support team.
Thank you!

Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • March 25, 2024
If the data is already being sent Chronicle, you would just need to do a
search for the appropriate fields.

If it’s not, you will most likely need to setup a forwarder or use the
ingestion api to get that data into Chronicle.

If you have not done that yet, please open a ticket with our support team.
Thank you!

Hi ,

I got it Thanks ! Appreciate your help 🙂