The purpose of this document is to provide set up information on the ArcSight integration.
ArcSight is a Syslog service developed by HP and is available at the systems which offer the Syslog feature. To date that is only HIAB.
Before enabling ArcSight in the HIAB, the ArcSight server need to be set up and configured.
Set Up ArcSight
To enable ArcSight:
- Go to Menu > Settings > Integrations.
- Select the Syslog tab.
- Check the Arcsight: checkbox as shown in the figure.
- Click Save.
When ArcSight is enabled, the Syslog message is built differently to fit into the ArcSight protocol.
When a Syslog event is activated, an ArcSight message is built instead of the ordinary Syslog message.
The Syslog message is sent to the ArcSight logger or the connector. When the logger shows the message, it is divided into columns that is easier to work with than the raw data.
No ArcSight specific errors should occur. If the ArcSight server has errors it is due to the Syslog implementation, not the ArcSight implementation.
It is recommended that the customer uses ArcSight together with TLS. If the logger cannot work with the TLS messages, a connector is recommended to be able to do so.
There is no maintenance needed for ArcSight, but the logger or the Syslog settings must be updated if IP numbers or other information are switched.
A Syslog Message
An ArcSight Message
© 2022 Outpost24® All rights reserved. This document may only be redistributed unedited and unaltered. This document may be cited and referenced only if clearly crediting Outpost24® and this document as the source. Any other reproduction and redistribution in print or electronically is strictly prohibited without explicit permission.
Outpost24® and OUTSCAN™ are trademarks of Outpost24® in Sweden and other countries.