Paladion ArcSight Training2
Paladion ArcSight Training2
• ArcSight Express All-in-One has the Oracle Enterprise Linux operating system
installed. Set up the preferences for Oracle Enterprise Linux when you boot the
system for the first time only or when you boot the system after a factory restore.
• The following wizard will help you set the preferences for Oracle Enterprise Linux:
• Click Next on the Welcome screen
PRESENTATION NAME
Continued..
Continued
PRESENTATION NAME
PRESENTATION NAME
PRESENTATION NAME
To install ArcSight Console, run the self-extracting archive file and click Next in the following screens.
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
ArcSight Console Installation
Arcsight Console
Console
• Navigator Panel
• Viewer Panel
• Inspect/Edit Panel
• Message bar
Navigator Panel
Actions taken within the console can also change default behavior
–Examples
• Showing Column Headers –Text Only, Icon and Text or Icon Only
• Browser settings
Network & Asset Modeling
What is Asset? Zone? Network? Customer?
• Assets represent individual nodes on the network, such as servers,
routers, and laptops
• Asset ranges represent a set of network nodes addressable as a
contiguous block of IP addresses
• Zones represent portions of the network itself and are also
characterized by a contiguous block of addresses
• Networks are helpful when disambiguating two private address
spaces
• Customers describe the internal or external cost centers or separate
business units associated with networks, if applicable to your
business environment
Event in ArcSight ESM Without Asset
Modeling
• No Customer
• No Model Confidence
• No Asset Criticality
• Priority 4
• Attacker Zone default
• Target Zone default
• No Geo Information at all
How ArcSight ESM Enriches Events
• Click on Categories
• Add Criticality
How ArcSight ESM Enriches Events
Step 5: Add Network and Customer to the Connector
How ArcSight ESM Enriches Events
• Customer ArcSight UC
• Model Confidence 4
• Asset Criticality 10
• Priority 5
• Attacker Zone populated
• Target Zone populated
How ArcSight ESM Enriches Events
• Model Confidence 10
• Relevance 10
• Asset Criticality 10
• Priority 5
How ArcSight ESM Enriches Events
Operators
= Is On
!= InSubnet InGroup
Contains Between BitAnd
In <
Startswith
<=
Endswith
Like >
>=
Filters
Number or CustomNumber1 = 50
=, !=, <, <=, >=, <, and In
Integer Aggregated Event Count >= 10
In the case sensitive column, select the check box if the data field value must
be case sensitive.
In the negate condition column, select the check box to change the condition
statement to an “all except this condition statement”.
Field Sets
Image Graph
View View
Grid
View
Active Channel
Active Channel
Rules
Rules
Join Rule
When a rule that has a notification action triggers, the ArcSight notification
engine does the following:
• Notify all active destinations in the first escalation level within that group.
The notification engine then waits for a certain time period to receive an
acknowledgment to that notification.
• The length of time that the notification engine waits for acknowledgement
depends on the event severity, and can be set.
• If no acknowledgment is received within the specified time interval, the same
notification is escalated to the next level within the group.
Notifications
Notification Icon
Notification Window
Notifications
Pending These are notifications that you have not yet handled.
Acknowledged These are notifications to which you have replied.
Pending notifications older than 24 hours are automatically
Not Acknowledged
refilled as Not Acknowledged.