Can be run on demand via UI, on a schedule, or over the Logger API. – Output formats include HTML, PDF, MS Excel, CSV, MS Word, Interactive HTML, XML .. Guide (PDF) 3 Understanding the User Interface 24 ArcSight Connector Appliance .. ArcSight Logger, ArcSight NCM, SmartConnector, ArcSight Threat. Contents 6 ESM Installation and Configuration Guide Confidential How do Configuration Guide Confidential /opt/arcsight A.

Author: Tataur Meztigis
Country: Myanmar
Language: English (Spanish)
Genre: Relationship
Published (Last): 10 September 2006
Pages: 209
PDF File Size: 9.99 Mb
ePub File Size: 5.86 Mb
ISBN: 279-2-72455-697-3
Downloads: 61684
Price: Free* [*Free Regsitration Required]
Uploader: Tojinn

When you run a search, the results show up at the bottom of the screen, most recent log on top. Search strings are case sensitive, arcsght multiple words should be included in quotations. All Peers The default is unchecked and searches only the local logger you are connected to.

NXLog User Guide | Log Management Solutions

You can also build more complex queries once you know what you are looking for and in which field Arcsight is logging that information. To use a previously saved filter or search, click on the load saved search or filter icon.

Please note this field is based on the time that Arcsight received the log, not necessarily the time of the event itself.

Include raw data samples in search results Select this to include samples of raw data in your sightings search results.

Include raw data samples in search results. The name of this configuration. Proceed to step 5. Configuring this integration activates workflows. When you log in, loggwr will be brought to the Analysis search page where you can search through all the logs oogger have access to in Arcsight to find the events you are looking for using basic search queries. This allows you to display only relevant fields for your results, removing fields that may not have meaning for what you are searching for.


The earliest results you want to see in number of days. To make the field set available for later use, hit Save. Enter the string you are searching for here, or build zrcsight search query using the Arcsight column headers. The user interface allows you to add and remove fields as well as put them in the order that you want.

Field Description Name The name of this configuration. Max Rows The maximum number of rows you want to search. Once you log out of Arcsight, the field set will not be saved. When checked, it searches all the loggers that are connected to one another.

Load Saved Search or Filter: To manage the workflows, navigate to the Workflow Editor. You can also activate the plugin using the traditional method. Since there are dozens of fields that can be logged in Arcsight, using this feature will save you the time of scrolling through unnecessary data to find what you are looking for. The default is unchecked and searches only the local logger you are connected to. When you save a field set, it will appear under the Shared Fieldsets category and will be visible to all other users of Arcsight.

Search Queries Search queries can be as simple as entering a ligger name, IP address, or other string you are interested in looking for.

ArcSight Logger configuration backup and restoration

See the Field Set yuide below for more information. The amount of data returned depends on your setting in the number of rows of raw data property in Security Incident Response properties. Select this to include samples of raw data in your sightings search results. This procedure can be used to activate the plugin and configure the integration.

The Security Integration screen reloads and the New button for the integration is available. Be careful not to uswr existing filters this way that are not yours. The available security integrations appear as a series of cards.


Saved search saves the query expression and the time range that you See the Filters and Saved Searches section below for more information. Please do not use this feature! Use these buttons to customize your field set. Search Logs To search for logs in Arcsight, go to https: Enter a name for the search or filter. Select the time range you wish to search the logs for.

Normally these times are identical, but some situations may cause a lag between the event and Arcsight receiving it. Filters save the query expression, but do not save the time range or the field set information. For example, if I want to show all Weblogin events for a certain person, I can find them by typing: This tool allows you to save a query that you use frequently as a filter or a saved search.

Guise you activate the plugin using the traditional method, the HPE ArcSight Logger – Incident Enrichment integration recognizes the installation and the integration card displays the New button. The maximum number of rows you want to search.

Management Center 2.1 User’s Guide

The query will be entered into the search box for you; click Go after adjusting your time range as needed. See the Search Queries section below. Earliest Result days The earliest ardsight you want guuide see in number of days. Choose whether to save it as a filter or a saved search, then hit save. If you click OK after customizing your field set, it will only be available to you for your current session.