11.1 Integration with SIEM Solutions

Change Guardian and the SIEM solution products, such as Micro Focus Sentinel Enterprise, Splunk Enterprise Security, and ArcSight Enterprise Security Manager are security monitoring solutions. Change Guardian provides focused security for change details and privilege user monitoring, and can forward these specialized change monitoring details to other SIEM solutions for consolidated monitoring, correlations and analysis.

SIEM Product Name

Event Forwarding Mechanism

Sentinel

REST Dispatcher or Syslog Dispatcher

Splunk Enterprise Security

Syslog Dispatcher

ArcSight Enterprise Security Manager

Syslog Dispatcher

In Sentinel you can analyze the change events forwarded by Change Guardian, while the other SIEM solution products use Change Guardian to analyze the data.

To configure event forwarding to other SIEM solution products, see Configuring Event Destinations.