Skip to content
Just migrated our o...
 
Notifications
Clear all

Just migrated our on-prem ArcSight to a cloud instance. The pain was real, AMA.

4 Posts
4 Users
0 Reactions
3 Views
(@grafana_guy_night)
Reputable Member
Joined: 4 months ago
Posts: 126
Topic starter   [#21310]

Just finished a 3-week migration from our old ArcSight ESM box to a cloud-hosted version. I thought my Grafana/Prometheus migrations were tough, but this was another level 😅

Biggest hurdles were the log source reconfiguration and making sure all our parsers and rules carried over. Had to manually re-map a ton of network device syslog targets. Also, the cost model in the cloud is... eye-opening. Anyone else been through this? Would love to hear about your gotchas or if you found any clever automation for the connector re-registration.



   
Quote
(@emmal)
Estimable Member
Joined: 1 week ago
Posts: 69
 

I haven't done this migration myself, but I've been looking at cloud SIEM costs for our own planning. When you say the cost model is eye-opening, do you mean the connector-based licensing or the data ingestion fees? Our team is worried about unpredictable spikes from syslog sources flooding in.

I'm also curious about the parser and rule carry-over. Did the cloud version have any compatibility issues with your existing rules, or was it just a tedious manual export/import?



   
ReplyQuote
(@coffeegoblin)
Estimable Member
Joined: 1 week ago
Posts: 82
 

Three weeks sounds optimistic. With our on-prem setup, the pain at least had a predictable capital expense curve. The cloud's "eye-opening" cost model is the real migration, just deferred. You're trading a one-time reconfiguration nightmare for a perpetual, variable-rate one.

Did your contract at least lock in the connector pricing, or are you now at the mercy of their quarterly "feature-based" re-tiering? I've seen bills double after the first year once the initial migration discounts vanish. The manual re-mapping you mentioned is just the first invoice.


Buyer beware.


   
ReplyQuote
(@chrisk)
Estimable Member
Joined: 1 week ago
Posts: 90
 

It's both, but the ingestion fees are the real variable cost. Connectors are predictable; your syslog volume rarely is. We saw a 40% increase in parsed EPS (events per second) post-migration, not from new sources, but because the cloud processing pipeline applied slightly different normalization. That directly hit the bill.

On parser and rule carry-over, it was mostly tedious export/import, but we did hit a few edge cases. Certain legacy flex connector parsers referencing on-prem file paths for lookup tables broke. The cloud instance couldn't resolve them. We had to migrate those to internal resource objects, which added about a day of scripting.

I'd recommend you run a parallel ingest test with a subset of your noisiest sources for a week before committing. Capture the EPS delta between your on-prem ESM and the cloud tenant's reported ingested volume. That gap is your new baseline cost.



   
ReplyQuote