1
ArcSight Logger Start up configuration steps are: Analysis (meeting at beginning of service) Connector analysis: data source type/number/location Retention Policy definition • Planning of monitoring effectiveness in base of EPS/days/storage Group of users, type of operation and access to logs Backup and archival requirements Implementation Preparation of Logger appliance (OS patch, ...) Configuration of Logger appliance (receiver, device group, storage, retention policy,user groups) Configuration of Connector appliance (if present) Configuration of a maximum of 4 ArcSight SmartConnectors (on Logger appliance/Connector appliance or external server) of different type and setup of a system together with end user system administrator (ie: acquisition of oneWindow server, one Linux server, one instance of Oracle, … ). Configuration of Management for remote Connectors Configuration of 1 type of filters on the connector – if necessary tight to retention policy application Creation of search filters for 3 user groups with different visibility of events Setup of scheduled Backup and archive of log data Example of creation of a simple search, a report and an alert ArcSight JumpStart Service ArcSight 3 days Logger JumpStart Service What is the benefit of the JumpStart Service? An ArcSight certified specialist helps your team to deploy, configure in a way that allow generation and further acquisition of logs. Throughout such an engagement, the ArcSight consultant records all findings, end user requirements, solutions developed, and recommendations for better utilizing the system. THE TEAM YOUR TEAM Interested? Please contact our Consultancy / Project Desk Email: [email protected] Phone: + 32 (0)2 461 01 44

ArcSight 3 days Logger JumpStart Service - Westcon …be.security.westcon.com/documents/39500/arcsight_starter...ArcSight Logger Start up configuration steps are: Analysis (meeting

Embed Size (px)

Citation preview

Page 1: ArcSight 3 days Logger JumpStart Service - Westcon …be.security.westcon.com/documents/39500/arcsight_starter...ArcSight Logger Start up configuration steps are: Analysis (meeting

ArcSight Logger Start up configuration steps are:

Analysis (meeting at beginning of service) Connector analysis: data source type/number/location Retention Policy definition •PlanningofmonitoringeffectivenessinbaseofEPS/days/storage Groupofusers,typeofoperationandaccesstologs Backupandarchivalrequirements

Implementation PreparationofLoggerappliance(OSpatch,...) ConfigurationofLoggerappliance(receiver,devicegroup,storage,retentionpolicy,usergroups) ConfigurationofConnectorappliance(ifpresent) Configurationofamaximumof4ArcSightSmartConnectors(onLoggerappliance/Connectorapplianceorexternalserver) ofdifferenttypeandsetupofasystemtogetherwithendusersystemadministrator(ie:acquisitionofoneWindowserver, oneLinuxserver,oneinstanceofOracle,…). ConfigurationofManagementforremoteConnectors Configurationof1typeoffiltersontheconnector–ifnecessarytighttoretentionpolicyapplication Creationofsearchfiltersfor3usergroupswithdifferentvisibilityofevents SetupofscheduledBackupandarchiveoflogdata Exampleofcreationofasimplesearch,areportandanalert

ArcSight JumpStart Service

ArcSight 3 days Logger JumpStart Service

What is the benefit of the JumpStart Service? AnArcSightcertifiedspecialisthelpsyourteamtodeploy,configureinawaythatallowgenerationandfurtheracquisitionoflogs.Throughoutsuchanengagement,theArcSightconsultantrecordsallfindings,enduserrequirements,solutionsdeveloped,andrecommendationsforbetterutilizingthesystem.

THE TEAM

YOUR TEAM

Interested? Please contact our Consultancy / Project Desk Email: [email protected] Phone: + 32 (0)2 461 01 44