Microsoft Sentinel
Cloud and workloads

Migration Arcsight Historical Data

In brief

The documentation updates its publication metadata and clarifies that event data retrieved from ESM can be combined with unstructured data alongside CEF data. The listed export formats remain CEF, CSV, and key-value pairs.

What Defender admins need to know

No administrator action is required; the update improves documentation clarity.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to export historical data from ArcSight so that I can migrate it to a new platform for further analysis and storage.

Use the Event Data Transfer tool to export data from ArcSight Enterprise Security Manager (ESM) version 7.x. To export data from ArcSight Logger, use the lacat utility.

The Event Data Transfer tool retrieves event data from ESM, which allows you to combine analysisESM. This event data can be combined with unstructured data,data in addition to the CEF data. The Event Data Transfer tool exports ESM events in three formats: CEF, CSV, and key-value pairs.

To export data using the Event Data Transfer tool: