Logger to Logger Data Migration
From time to time, I get into customers that have been using ArcSight Logger for a couple of months as a POC box and once they make their decision to buy the Logger appliance from HP, they are looking for options to migrate data from the POC Logger to the newly purchased Logger without going through archive process that requires a permanent external storage. This post walks you through the steps to have a smooth data migration from one Logger to another.
Step 1: To keep the logs organized, create a new Storage Group with the proper size and retention time.
Step 2: In the new Logger, browse to “Configuration | Event Input” section and create a new receiver with the configuration that is demonstrated in Figure 2.
Step 3: Enable the created the CEF TCP receiver.
Step 4: In the new Logger, browse to “Configuration | Devices” section and create a new Device with the IP address of the POC Logger and the receiver that got created in step 2.
Step 5: In the new Logger, browse to “Configuration | Devices” section and create a new Device Group called “Historical Events” and add the relevant devices to the new Device Group.
Step 6: In the new Logger, browse to “Configuration | Storage” section and create a new Storage Rule that maps the created Device Group in Step 5 to the Storage Group that was created in Step 1.
Step 7: In the old Logger, browse to “Configuration | Event Output” section and create a new forwarder as demonstrated in Figure 6.
Step 8: Click Next and then select the proper query and time range to select the events that should be migrated. It is also important that the port matches with what is configured on the new Logger in step 2. Click
Step 9: Click on Save and enable the forwarder once you are ready for the data migration.
The data migration will start a few minutes after the forwarder is enabled. Keep in mind that the speed of the data transfer depends on the network bandwidth and also the IOPS rate on the Logger appliance, but on average you can expect about 15,000 events to be transferred every second.