Created 02-15-2025 10:08 PM
Hello,
I need your guidance on the following scenario:
We have a SIEM (QRadar) infrastructure where Event Collectors receive logs from various data sources. These logs are correlated based on SIEM rules and use cases.
we plan to send logs to the SIEM while also storing a copy in a Data Lake.
Current Approach:
We have structured the workflow as follows:
DATA SOURCES → NiFi → Store in DATA LAKE & Forward to SIEM (using PUTTCP processor)
Questions:
thanks in advance
Created 02-18-2025 05:59 AM
@MarinaM
Welcome to the Cloudera Community.
Your Questions:
Please help our community grow and thrive. If you found any of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "Accept as Solution" on one or more of them that helped.
Thank you,
Matt
Created 02-17-2025 02:05 AM
@MarinaM, Welcome to our community! To help you get the best possible answer, I have tagged our NiFi experts @MattWho @satz who may be able to assist you further.
Please feel free to provide any additional information or details about your query, and we hope that you will find a satisfactory solution to your question.
Regards,
Vidya Sargur,Created 02-18-2025 05:59 AM
@MarinaM
Welcome to the Cloudera Community.
Your Questions:
Please help our community grow and thrive. If you found any of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "Accept as Solution" on one or more of them that helped.
Thank you,
Matt