SlideShare a Scribd company logo
1 of 18
Download to read offline
Release Notes
ArcSight ESM
Version 6.8c Patch 2
October 29, 2015
Copyright © 2015 Hewlett-Packard Development Company, L.P.
Confidential computer software. Valid license from HP required for possession, use or copying. Consistent
with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and
Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard
commercial license.
The information contained herein is subject to change without notice. The only warranties for HP products
and services are set forth in the express warranty statements accompanying such products and services.
Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for
technical or editorial errors or omissions contained herein.
Follow this link to see a complete statement of copyrights and acknowledgements:
http://www.hpenterprisesecurity.com/copyright
Contact Information
R
Revision History
Phone A list of phone numbers for HP ArcSight Technical Support is
available on the HP Enterprise Security contacts page:
https://softwaresupport.hp.com/documents/10180/14684/esp-
support-contact-list
Support Web Site http://softwaresupport.hp.com
Protect 724 Community https://protect724.hp.com
Date Product Version Description
10/29/2015 ArcSight ESM Version 6.8c
Patch 2
Release Notes for ArcSight ESM Version 6.8c Patch 2.
Confidential Release Notes ArcSight ESM 6.8c Patch 2 3
Contents
ArcSight ESM Version 6.8c Patch 2 ......................................................................................................... 5
ESM 6.8c Patch 2 ............................................................................................................ 5
Purpose of this Patch ....................................................................................................... 5
Usage Notes for this Patch ................................................................................................ 5
Update Case Customizations in a Localized Environment ................................................ 5
ArcSight Web Configuration for PKCS#11/CAC .............................................................. 6
MSSP - Specific Settings ............................................................................................ 6
Section 508 Compliance ................................................................................................... 6
Geographical Information Update ...................................................................................... 6
Vulnerability Updates ....................................................................................................... 6
Installing ESM Version 6.8c Patch 2 ................................................................................... 7
Verify ESM 6.8c Patch 2 Files ...................................................................................... 9
ArcSight ESM Main Component Suite ........................................................................... 9
ArcSight Console ..................................................................................................... 11
Issues Fixed in this Patch ............................................................................................... 14
Analytics ................................................................................................................ 14
ArcSight Console ..................................................................................................... 14
ArcSight Manager .................................................................................................... 16
CORR-Engine .......................................................................................................... 16
Command Center .................................................................................................... 16
Open Issues in this Patch ............................................................................................... 18
ArcSight Console ..................................................................................................... 18
Installation and Upgrade .......................................................................................... 18
Issues Fixed in ESM 6.8c Patch 1 ..................................................................................... 18
Analytics ................................................................................................................ 18
ArcSight Console ..................................................................................................... 19
ArcSight Manager .................................................................................................... 19
CORR-Engine .......................................................................................................... 19
Command Center .................................................................................................... 19
Installation and Upgrade .......................................................................................... 19
Open and Closed Issues in ESM 6.8c ................................................................................ 20
4 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
Contents
Confidential Release Notes ArcSight ESM 6.8c Patch 2 5
ArcSight ESM Version 6.8c Patch 2 
ESM 6.8c Patch 2
These release notes describe how to apply this patch release of ArcSight ESM. Instructions
are included for each component, as well as other information about recent changes and
open and closed issues.
This patch is for ArcSight ESM 6.8c only. To set up a new ESM 6.8c installation, refer to the
ArcSight ESM Installation and Configuration Guide.
The build number for the ESM suite for this patch is 1941.
The build number for the ArcSight Console for this patch is 2108.2.
After you have installed 6.8c, follow the instructions in “Installing ESM Version 6.8c Patch
2” on page 7 of these release notes to apply Patch 2.
Purpose of this Patch
This patch:
 Addresses critical issues in ESM 6.8c; applicable to ESM 6.8c with or without ESM 6.8c
patches.
 Provides updates for geographical information and vulnerability mapping.
 Provides important security updates.
 Numerous Japanese language translation improvements
 refer to the HP ArcSight ESM Support Matrix for the new and existing operating
systems supported in this patch.
Usage Notes for this Patch
Refer to ArcSight ESM Release Notes for versions 6.8c. The usage notes for those releases
also apply to this patch.
Update Case Customizations in a Localized Environment
When you install ESM 6.8c Patch 2, case customizations you made to the configuration are
not preserved in the new installation. To regain your customizations, after installing ESM
6.8c Patch 2, copy the sections or lines having any case customizations in the Console and
Manager
<ARCSIGHT_HOME>i18ncommonlabel_strings_<locale>.properties and
<ARCSIGHT_HOME>i18ncommonresource_strings_<locale>.properties
files from the backup of your previous installation into those corresponding files in your
current installation. Restart Manager and UI to see the customizations.
Section 508 Compliance
6 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
ArcSight Web Configuration for PKCS#11/CAC
These steps to configure PKCS#11/CAC for the ArcSight Web are not in the Installation
Guide.
To configure:
1 Import the CAC card’s root CA certificate into Web’s
<ARCSIGHT_HOME>configjettywebtruststore directory.
2 Set ArcSight Web’s authentication to Password Based or SSL Client Based
Authentication through webserversetup.
For further details, see the ESM Administrator’s Guide.
MSSP - Specific Settings
In a managed security service provider (MSSP) environment, change the setting to disable
the search auto-complete feature. To do this, in the logger.properties file change the
value of auto-complete.fulltext.enabled to false and restart services.
Section 508 Compliance
ArcSight recognizes the importance of accessibility as a product initiative. To that end,
ArcSight continues to make advances in the area of accessibility in its product lines.
Geographical Information Update
This version of ESM includes an update to the geographical information used in graphic
displays. The version is GeoIP-532_20151001.
Vulnerability Updates
This release includes recent vulnerability mappings from the October 2015 Context Update.
Device Vulnerability Updates
Snort / Sourcefire SEU 1362 updated Faultline, Bugtraq, CVE, X-Force, Nessus
Enterasys Dragon IDS updated CVE
Cisco Secure IDS S888 updated CVE
Juniper / Netscreen IDP update 2535
updated
Faultline, Bugtraq, CVE, X-Force, Nessus,
MSSB, CERT
McAfee Intrushield 8.7.63.4 updated Faultline, Bugtraq, CVE, Nessus, X-Force,
MSSB, CERT
TippingPoint UnityOne DV8755
updated
Faultline, Bugtraq, CVE, Nessus
IBM Enterprise Scanner 1.137
updated
CVE, X-Force
IBM Security Host Protection for
Desktops 3180 updated
Faultline, CVE, Nessus, X-Force
IBM Security Host Protection for
Servers (Unix) 35.100 updated
Faultline, CVE, Nessus, X-Force
Installing ESM Version 6.8c Patch 2
Confidential Release Notes ArcSight ESM 6.8c Patch 2 7
Installing ESM Version 6.8c Patch 2
You can install this patch release using the platform-specific component executable files
provided. Patch installers are available for all supported platforms. Please keep the
following points in mind when installing Patch 2:
Each component has install and uninstall steps.
Verify ESM 6.8c Patch 2 Files
HP provides a digital public key to enable you to verify that the signed software you
received is indeed from HP and has not been manipulated in any way by a third party.
Visit the following site for information and instructions:
https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPL
inuxCodeSigning
IBM Security Host Protection for
Servers (Windows) 3180 updated
Faultline, CVE, Nessus, X-Force
IBM Proventia Network IPS 35.100
updated
Faultline, Bugtraq, CVE, Nessus, X-Force,
MSSB
IBM Proventia Network MFS 35.100
updated
Faultline, Bugtraq, CVE, Nessus, X-Force,
MSSB
IBM Proventia Server IPS for Linux
technology 35.100 updated
Faultline, CVE, Nessus, X-Force
IBM RealSecure Server Sensor XPU
35.100 updated
Faultline, CVE, Nessus, X-Force
McAfee HIPS 7.0/8.0 content version
6661 updated
CVE
• For all components and platforms: Make sure that you have enough
space available before you install the patch. The installer checks for 1 GB
of space and generates an error if it is not available. If you run into disk
space issues during installation, create enough space, restore the
component base build from the backup, then resume patch installation.
• Backup, patch install, and uninstall procedures require permissions for the
relevant components. To install a patch, make sure that the user who
owns the base build installation folder has full privileges on the PATH
where the base build is installed.
• To uninstall the software you must be at the same user level as the
original installer.
• It is a good practice to create a backup of the existing product before
installation begins. Do not simply rename files and leave them in the
same directory. Java reads all the files present, regardless of renaming,
and can pick up old code inadvertently, causing undesirable results.
• For backup, patch install, and uninstall, we recommend that you log in to
the target machine with a specific account name via telnet or SSH. If you
switch accounts after logging in, then specify the flag "-" for the su
command (su - <UserName>).
Device Vulnerability Updates
Installing ESM Version 6.8c Patch 2
8 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
ArcSight ESM Main Component Suite
This section describes how to install or uninstall the ESM 6.8c Patch 2 for all the main
components except the ArcSight Console. These components include the Manager, ArcSight
Web, and the CORR-Engine.
To Install the Patch
1 Download the patch from the HP Software Support Online site
(http://softwaresupport.hp.com).
ArcSightESMSuitePatch-XXXX.tar
...where XXXX represents the suite build number.
Be sure to verify the patch file; see “Verify ESM 6.8c Patch 2 Files” on page 7.
2 As user arcsight, extract the tar file.
3 From the directory where you extracted the tar file, as user root, run stop_services
with this command:
./stop_services.sh
4 Back up the ArcSight directory, /opt/arcsight, by making a copy. Place the copy in
a readily accessible location. This is a precautionary measure so you can restore the
system to the original state, if necessary.
5 Run the patch installer as user arcsight:
./ArcSightESMSuitePatch.bin
To install in Console mode, run the following command from the shell prompt and then
follow the instructions in the window:
./ArcSightESMSuitePatch.bin -i console
6 Read through the license agreement and accept it at the end. In GUI mode, the
acceptance radio button is disabled until you scroll to the bottom of the agreement. In
the console mode, press Enter until you have paged through to the end of the license
agreement.
7 Select a location for the uninstaller link, if you want to have a shortcut to the
uninstaller in some other location. You must have write permission to the specified
folder.
• Before you install the patch, verify that <ARCSIGHT_HOME> and any of its
subdirectories are not being accessed by open shells on your system.
• If for any reason you need to re-install the patch, run the patch
uninstaller before installing the patch again.
• HP recommends that you continue through the installation and do not
attempt to cancel the installation process or move backward through the
installer windows.
HP recommends that you do not simply rename files and leave them in
the same directory. Java reads all the files present, regardless of
renaming, and can pick up old code inadvertently, causing undesirable
results.
Installing ESM Version 6.8c Patch 2
Confidential Release Notes ArcSight ESM 6.8c Patch 2 9
8 Check the pre-installation summary to verify that all the locations listed are correct and
that you have enough disk space to install this patch.
9 Click Install.
10 Click Next on the File Delivery Complete screen to install the CORR-Engine, Manager,
and ArcSight Web components.
11 Click Done on the Install Complete screen.
12 As root, run the runAsRoot script with this command:
sh /opt/arcsight/suite/bin/runAsRoot.sh
Messages will result from running this script; ignore the errors No such file or
directory. Eventually, you will see the message: DONE: Set up ArcSight
services. Services begin initializing after runAsRoot completes, but all services
may take a short time to become fully available.
13 Check the ArcSight services as user arcsight:
/etc/init.d/arcsight_services status all
To Uninstall the Patch
If needed, use the procedure below to uninstall this patch installation and restore the
system to the pre-patched state.
1 As user root, run remove_services with this command:
sh /opt/arcsight/manager/bin/remove_services.sh
2 As user arcsight, run the uninstaller program from either the directory where you
created the link while installing the product or, if you had opted not to create a link,
then run this from the
/opt/arcsight/suitepatch_6.8.0.2/UninstallerData_6.8.0.2
directory:
./Uninstall_ArcSight_ESM_Suite_Patch
Alternatively, you can run the following command from the /home/arcsight (or
wherever you installed the shortcut link) directory:
./Uninstall_ArcSight_ESM_Suite_Patch_6.8.0.2
Or, to uninstall using Console mode, run:
./Uninstall_ArcSight_ESM_Suite_Patch_6.8.0.2 -i console
Run the uninstaller in the same mode in which you ran the installer (GUI or Console
mode).
3 Click Done on the Uninstall Complete screen.
4 As root, run setup_services with this command:
sh /opt/arcsight/manager/bin/setup_services.sh
Before you begin to uninstall, verify that the Manager’s <ARCSIGHT_HOME>
and any of its subdirectories are not being accessed by any open shells on
your system.
Installing ESM Version 6.8c Patch 2
10 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
ArcSight Console
This section describes how to install or uninstall the ESM 6.8c Patch 2 for ArcSight Console
on Windows, Mac, and Linux platforms.
To Install the Patch
1 Exit the ArcSight Console.
2 Back up the Console directory (for example, /home/arcsight/console/current)
by making a copy. Place the copy in a readily accessible location. This is a
precautionary measure so you can restore the original state, if necessary.
3 Download the executable file specific to your platform from the HP Software Support
Online site (http://softwaresupport.hp.com). YYYY.Y represents the Console build
number.
 Patch-6.8.0.YYYY.Y-Console-Win.exe
 Patch-6.8.0.YYYY.Y-Console-Linux.bin
 Patch-6.8.0.YYYY.Y-Console-MacOSX.zip
Be sure to verify the patch file; see “Verify ESM 6.8c Patch 2 Files” on page 7
For the Mac, see To Install the Patch on a Mac, below.
4 Run one of the following executables specific to your platform:
 On Windows:
Double-click Patch-6.8.0.YYYY.Y-Console-Win.exe
 On Linux:
Verify that you are logged in as user arcsight, and then run the following
command:
./Patch-6.8.0.YYYY.Y-Console-Linux.bin
The ArcSight ESM Console is not supported on AIX or Solaris. The following
steps do not include information for installing a Console patch on those
platforms.
• Before you install the patch, verify that the Console’s <ARCSIGHT_HOME>
directory and any of its subdirectories are not being accessed by any open
shells on your system.
• If you need to re-install the patch, run the patch uninstaller before
installing the patch again.
• HP recommends that you continue through the installation and do not
attempt to cancel the installation process or move backward through the
installer windows.
HP recommends that you do not simply rename files and leave them in
the same directory. Java reads all the files present, regardless of
renaming, and can pick up old code inadvertently, causing undesirable
results.
Installing ESM Version 6.8c Patch 2
Confidential Release Notes ArcSight ESM 6.8c Patch 2 11
To install in Console mode, run the following command from the shell prompt and
then follow the instructions in the window:
./Patch-6.8.0.YYYY.Y-Console-Linux.bin -i console
The installer launches the Introduction window.
5 Read the instructions provided and click Next.
6 Accept the terms of the license agreement and click Next. The acceptance radio
button is disabled until you scroll to the bottom of the agreement.
7 Enter the location of your existing <ARCSIGHT_HOME> directory for your Console
installation in the text box provided or navigate to the location by clicking Choose…
If you want to restore the installer-provided default location, click Restore Default
Folder.
8 Click Next.
9 Choose a Link Location (on Linux) or Shortcut location (on Windows) by clicking the
appropriate radio button and click Next.
10 Check the pre-installation summary to verify that all the locations listed are correct and
that you have enough disk space to install this patch.
11 Click Install.
12 Click Done on the Install Complete screen.
To Install the Patch on a Mac
The patch installer download and run procedure is slightly different on the Mac than on the
other supported platforms.
1 Exit the ArcSight Console.
2 Back up the Console directory (for example, /home/arcsight/console/current)
by making a copy. Place the copy in a readily accessible location. This is just a
precautionary measure so you can restore the original state, if necessary.
3 Download the file Patch-6.8.0.YYYY.Y-Console-MacOSX.zip to anywhere on
your system.
Be sure to verify the patch file; see “Verify ESM 6.8c Patch 2 Files” on page 7.
4 Launch the patch installer by double-clicking the ArcSightConsolePatch file.
5 Follow the steps on the patch install wizard, providing the information as prompted:
 Accept the terms of the license agreement and click Next. The acceptance radio
button is disabled until you scroll to the bottom of the agreement.
HP recommends that you continue through the installation and do not
attempt to cancel the installation process or move backward through the
installer windows.
The patch installer file shows as a ZIP file on the download site, but
downloads as ArcSightConsolePatch.app on the Mac. A single or
double-click on this APP file launches the patch installer, depending on
how you have set these options. There is no need to “extract” or “unzip”
the file; it downloads as an APP file.
Installing ESM Version 6.8c Patch 2
12 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
 Choose the location where you want to install the patch. Browse to
<ARCSIGHT_HOME>, where your previous Console was installed.
 Choose an alias location for the Console application (or opt to not use aliases).
This is the same as a link location on UNIX systems or shortcut location on
Windows systems.
6 Click Next.
7 Verify your settings and click Install.
To Uninstall the Patch
If needed, use the procedure below to uninstall this patch installation.
1 Exit the ArcSight Console.
2 Run the uninstaller program:
On Windows:
 Double-click the icon you created for the uninstaller when installing the Console.
For example, if you created an uninstaller icon on your desktop, double-click that
icon.
 If you created a link in the Start menu, click:
Start > All Programs > ArcSight ESM Console 6.8c Patch 2 > Uninstall
ArcSight ESM Console 6.8c Patch 2
 Or, run the following from the Console’s
<ARCSIGHT_HOME>currentUninstallerData_6.8.0.2 directory:
Uninstall_ArcSight_ESM_Console_Patch
 On Windows 8, run the following from the Console's
<ARCSIGHT_HOME>currentUninstallerData_6.8.0.2 directory:
Uninstall_ArcSight_ESM_Console_Patch.exe
On Linux:
 From the directory where you created the link when installing the Console (your
home directory or some other location), run:
./Uninstall_ArcSight_ESM_Console_Patch_6.8.0.2
 Or, to uninstall using Console mode, run:
./Uninstall_ArcSight_ESM_Console_Patch_6.8.0.2 -i console
 If you did not create a link, execute the command from the Console’s
<ARCSIGHT_HOME>/current/UninstallerData_6.8.0.2 directory:
./Uninstall_ArcSight_ESM_Console_Patch
On a Mac:
 From the directory where you created the link when installing the Console, run:
Uninstall_ArcSight_ESM_Console_Patch_6.8.0.2
Before you begin to uninstall, verify that the Console’s <ARCSIGHT_HOME> and
any of its subdirectories are not being accessed by any open shells on your
system.
Issues Fixed in this Patch
Confidential Release Notes ArcSight ESM 6.8c Patch 2 13
 From the Console’s
<ARCSIGHT_HOME>/current/UninstallerData_6.8.0.2 directory, run:
Uninstall_ArcSight_ESM_Console_Patch
3 Click Done on the Uninstall Complete screen.
Issues Fixed in this Patch
The following issues are fixed in this patch.
Analytics
ArcSight Console
If you are on a Windows system and you plan to uninstall the base build
Console after uninstalling Patch 2, be advised that your system restarts
without warning upon finishing the base build uninstallation.
Prepare your system accordingly.
Issue Description
NGS-14566 When a Query was constructed with a GROUP condition using 'Sum', SQL
generation would fail.
This issue is now fixed.
Issue Description
NGS-14933 "Bucket size in seconds" was not translated correctly into Japanese.
This issue is now fixed.
NGS-14791 Translations of "Required package For" and "Optional package For" were not
correct for Japanese.
This issue is now fixed.
NGS-14723 In some cases, event-based Active Channels that include an InCase filtering
condition do not display events that belong to a case but have been removed from
the main event table (arc_event) due to the retention period limit. Case-related
events are copied to a special table so they can remain available after being
archived, but the channel is unable to find and display such events correctly after
the partition is archived.
Workaround: Use the case event editor or Reports, which can correctly find and
display these events.
NGS-14721 The “Moving Average" field in the Console Dashboard was translated incorrectly in
Japanese.
This issue is now fixed.
NGS-14565 When case management was moved from ArcSight Web to ACC, the URL sent in
email notifications was not updated correctly and still pointed to Web.
This issue is now fixed.
NGS-14525 Some archived reports that have Japanese characters in their names had garbled
file names when downloaded, and the Japanese characters appeared blank.
This issue is now fixed.
Issues Fixed in this Patch
14 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
ArcSight Manager
NGS-14522 The Console displayed some incorrect Japanese translations.
• Login Console
• Bucket size in Seconds
• Number of Buckets
Also, the following are not translated into Japanese:
• The filtering being performed on the data monitor.
• Bucket size in Seconds
• Number of Buckets
• Time Filed
• The field to use for values
• The file to aggregate data on
This issue is now fixed.
NGS-14503 When using dual monitors (multiple display), filter operators would sometimes
display on the wrong monitor. This issue is now fixed.
NGS-14483 Added support for a Static Banner at the top of every Console user interface
connecting to a given Manager.
To do this, set the server.staticbanner.backgroundcolor,
server.staticbanner.textcolor and server.staticbanner.text properties in
server.properties and restart the Manager. The backgroundcolor and textcolor
properties only support the following color strings: black, blue, cyan, gray, green,
magenta, orange, pink, red, white, yellow.
If the server.staticbanner.text is not set or empty then banner panel will not
display. If the server.staticbanner.backgroundcolor is invalid or is not set then
default color green will be used. If the server.staticbanner.textcolor is invalid or is
not set then the default color black will be used.
NGS-12868 When using ArcSight Command Center to export a report to CSV format, if the
field set contained agentReceiptTime, the value was always blank because the
export mechanism expected the database field name instead of the display name.
This issue is now fixed.
Issue Description
NGS-14567 The value size calculations for integer/long/double values were incorrect, which
could result in errors saying "Event ... is too long for DB column size '19'." in
server.log.
This issue is now fixed.
NGS-13222 Shutting down services by using the arcsight_services command might result in
exceptions in the log file. These exceptions are due to an issue with the order in
which the components are shut down, and can be safely ignored.
NGS-13146 Shutting down services by using the arcsight_services command might result in
exceptions in the log file. These exceptions are due to an issue with the order in
which the components are shut down, and can be safely ignored.
Issue Description
Issues Fixed in this Patch
Confidential Release Notes ArcSight ESM 6.8c Patch 2 15
CORR-Engine
Command Center
NGS-12225 Importing a CSV file into an active list with entries with the characters n, b, t,
r (for example, C:usersrequests) causes the characters to appear erroneously
in the ESM active list entry (e.g. C:usersrequests shows up as C:usersequests).
Also, when this data is exported into a csv file, the data displays erroneously (n
causes a newline space in the csv data).
This issue is now fixed.
NGS-10678 Under certain circumstances, an exception occurred during event processing
which led to an EPS drop.
This issue is now fixed.
Issue Description
NGS-14248 Filters using Target and Attacker User Name fields were not working as expected
in active channels or reports when used with ignore case.
This issue is now fixed.
Issue Description
NGS-14722 Some archive reports with PDF format that have been ran and saved through
ArcSight Command Center couldn't be opened, and this error displays:
Cannot Run Report. Possible reason it might be invalid or No access to Report
Template or Query.
This issue is now fixed.
NGS-14525 Some archived reports that have Japanese characters in their names have garbled
file names when downloaded, and the Japanese characters are shown as blank.
This issue is now fixed.
Issue Description
Open Issues in this Patch
16 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
Open Issues in this Patch
The following issues are open in this patch.
ArcSight Console
Installation and Upgrade
Issues Fixed in ESM 6.8c Patch 1
The following issues are fixed in this patch.
Analytics
ArcSight Console
Issue Description
NGS-14853 On Windows, when uninstalling the base build after P2 has already been
uninstalled, after you run the uninstaller program and click Done, the system
restarts automatically. There is no prompt to let you choose whether to restart the
system.
Issue Description
NGS-12870 On the Windows platform, after uninstalling ArcSight ESM Console patch 6.8.0.2,
the UninstallerData_6.8.0.2 directory remains in the <Console/current> directory.
This folder prevents ArcSight Console ESM patch 2 from installing again.
Workaround: Delete ArcSight Console’s UninstallerData_6.8.0.2 directory. You can
now re-install ArcSight Console ESM patch.
Issue Description
NGS-11107 Mapping certain Session List Global Variables (composed of multiple fields of
different types) to a field with SetEventField action failed with errors.
NGS-10996 "Export to External System" action on a rule did not work properly.
NGS-9757 When a report included the "End Time" field, the time shown in that column was
in the manager time zone instead of adjusted to the report query timezone.
NGS-9505 If a rule contains an action to AddToActiveList, and the action (or the enclosing
trigger) is disabled, exporting the rule to the package will not include the
referenced ActiveList, because the dependency relationship is not stored correctly.
Consequently, importing the package on another system (either manually or
automatically via Content Sync) may result in the rule being marked invalid.
Issue Description
NGS-12752 When hotkeys were created for Profile Resources they did not work as expected.
Issues Fixed in ESM 6.8c Patch 1
Confidential Release Notes ArcSight ESM 6.8c Patch 2 17
ArcSight Manager
CORR-Engine
Command Center
Installation and Upgrade
NGS-11515 Data Monitors did not remember column field positions after being saved.
Issue Description
NGS-11274 When using two consoles, in some conditions if the case information was edited in
Console A, it was not replicated to Console B.
NGS-11273 When using two consoles, in some conditions if the case information was edited in
Console A, it was replicated to Console B immediately, but it was not replicated to
Console A when the case was edited in Console B.
NGS-11257 Prior to this fix, the password was not updated if it does not match the policy
enforced (minimum length, previous password, etc.). The script would also
silently fail meaning no error messages were displayed so the user would not
know that the password was not updated.
Issue Description
NGS-13403 Case sensitive and insensitive queries sometimes returned wrong results when
stored procedures or functions that return strings were used. Hence Active
channels, Query Viewers and Reports gave wrong output when filtering events
with and with out the Ignore Case option.
Note that there is a limitation to this fix in Russian locale as the version of MySQL
used in the product has limitations with Cyrillic characters.
NGS-11262 Under certain circumstances, a Signal 11 crash could occur within mysqld.
Issue Description
NGS-13631 When a query involving "OR" was used on the ArcSight Command Center in a
multi-tenant environment, customer-specific filtering failed.
Issue Description
NGS-11761 Issuing a 'arcsight_services stop' command when all services are down resulted in
a failure 10 minutes later.
NGS-9142 Under certain circumstances, arcsight_services would report inconsistent status
alternating between "available" and "unavailable".
Issue Description
Open and Closed Issues in ESM 6.8c
18 Release Notes ArcSight ESM 6.8c Patch 2 Confidential
Open and Closed Issues in ESM 6.8c
For information about open and closed issues for ESM 6.8c, see the release notes for that
version.

More Related Content

What's hot

ESM 6.9.1c Patch1 Release Notes
	ESM 6.9.1c Patch1 Release Notes 	ESM 6.9.1c Patch1 Release Notes
ESM 6.9.1c Patch1 Release Notes Protect724tk
 
Arcsight ESM Support Matrix
Arcsight ESM Support MatrixArcsight ESM Support Matrix
Arcsight ESM Support MatrixProtect724
 
ArcSight Express 4.0 Patch 1 release notes
ArcSight Express 4.0 Patch 1 release notesArcSight Express 4.0 Patch 1 release notes
ArcSight Express 4.0 Patch 1 release notesProtect724v2
 
Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154Protect724
 
ESM 6.9.1c Patch 2 Release Notes
ESM 6.9.1c Patch 2 Release NotesESM 6.9.1c Patch 2 Release Notes
ESM 6.9.1c Patch 2 Release NotesProtect724tk
 
Esm install guide_5.2
Esm install guide_5.2Esm install guide_5.2
Esm install guide_5.2Protect724v3
 
Cisco Monitoring Standard Content Guide for ESM 6.5c
Cisco Monitoring Standard Content Guide for ESM 6.5c	Cisco Monitoring Standard Content Guide for ESM 6.5c
Cisco Monitoring Standard Content Guide for ESM 6.5c Protect724migration
 
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...Protect724v2
 
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154Protect724
 
ESM 6.9.1c Patch 3 Release Notes
ESM 6.9.1c Patch 3 Release NotesESM 6.9.1c Patch 3 Release Notes
ESM 6.9.1c Patch 3 Release NotesProtect724tk
 
Intrusion Monitoring Standard Content Guide
Intrusion Monitoring Standard Content GuideIntrusion Monitoring Standard Content Guide
Intrusion Monitoring Standard Content GuideProtect724
 
Esm rel notes_6.8cp4
Esm rel notes_6.8cp4Esm rel notes_6.8cp4
Esm rel notes_6.8cp4Protect724v3
 
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-EngineArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-EngineProtect724
 
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...Protect724v2
 
ArcSight Connector Appliance 6.4 Administrator's Guide
ArcSight Connector Appliance 6.4 Administrator's GuideArcSight Connector Appliance 6.4 Administrator's Guide
ArcSight Connector Appliance 6.4 Administrator's GuideProtect724tk
 

What's hot (18)

ESM 6.9.1c Patch1 Release Notes
	ESM 6.9.1c Patch1 Release Notes 	ESM 6.9.1c Patch1 Release Notes
ESM 6.9.1c Patch1 Release Notes
 
Arcsight ESM Support Matrix
Arcsight ESM Support MatrixArcsight ESM Support Matrix
Arcsight ESM Support Matrix
 
ESM 6.5 Patch 1 Release Notes
ESM 6.5 Patch 1 Release NotesESM 6.5 Patch 1 Release Notes
ESM 6.5 Patch 1 Release Notes
 
ArcSight Express 4.0 Patch 1 release notes
ArcSight Express 4.0 Patch 1 release notesArcSight Express 4.0 Patch 1 release notes
ArcSight Express 4.0 Patch 1 release notes
 
Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154
 
Upgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8cUpgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8c
 
ESM 6.9.1c Patch 2 Release Notes
ESM 6.9.1c Patch 2 Release NotesESM 6.9.1c Patch 2 Release Notes
ESM 6.9.1c Patch 2 Release Notes
 
Esm install guide_5.2
Esm install guide_5.2Esm install guide_5.2
Esm install guide_5.2
 
Cisco Monitoring Standard Content Guide for ESM 6.5c
Cisco Monitoring Standard Content Guide for ESM 6.5c	Cisco Monitoring Standard Content Guide for ESM 6.5c
Cisco Monitoring Standard Content Guide for ESM 6.5c
 
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
 
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
 
ESM 6.9.1c Patch 3 Release Notes
ESM 6.9.1c Patch 3 Release NotesESM 6.9.1c Patch 3 Release Notes
ESM 6.9.1c Patch 3 Release Notes
 
ESM_InstallGuide_5.6.pdf
ESM_InstallGuide_5.6.pdfESM_InstallGuide_5.6.pdf
ESM_InstallGuide_5.6.pdf
 
Intrusion Monitoring Standard Content Guide
Intrusion Monitoring Standard Content GuideIntrusion Monitoring Standard Content Guide
Intrusion Monitoring Standard Content Guide
 
Esm rel notes_6.8cp4
Esm rel notes_6.8cp4Esm rel notes_6.8cp4
Esm rel notes_6.8cp4
 
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-EngineArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
 
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
 
ArcSight Connector Appliance 6.4 Administrator's Guide
ArcSight Connector Appliance 6.4 Administrator's GuideArcSight Connector Appliance 6.4 Administrator's Guide
ArcSight Connector Appliance 6.4 Administrator's Guide
 

Similar to ESM 6.8c Patch 2 Release Notes

ArcSight Express 4.0 Virtual Appliance Guide
ArcSight Express 4.0 Virtual Appliance GuideArcSight Express 4.0 Virtual Appliance Guide
ArcSight Express 4.0 Virtual Appliance GuideProtect724v2
 
ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes	ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes Protect724mouni
 
ESM 6.9.1c Release Notes
ESM 6.9.1c Release NotesESM 6.9.1c Release Notes
ESM 6.9.1c Release NotesProtect724tk
 
Esm rel notes_6.9.0
Esm rel notes_6.9.0Esm rel notes_6.9.0
Esm rel notes_6.9.0Protect724v2
 
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1Protect724mouni
 
Model Import Connector for RepSM Release Notes
Model Import Connector for RepSM Release NotesModel Import Connector for RepSM Release Notes
Model Import Connector for RepSM Release Notesprotect724rkeer
 
ArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release NotesArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release NotesProtect724mouni
 
ArcSight Connector Appliance v6.1 Release Notes
ArcSight Connector Appliance v6.1 Release NotesArcSight Connector Appliance v6.1 Release Notes
ArcSight Connector Appliance v6.1 Release NotesProtect724tk
 
ESM Service Layer Developers Guide for ESM 6.8c
ESM Service Layer Developers Guide for ESM 6.8cESM Service Layer Developers Guide for ESM 6.8c
ESM Service Layer Developers Guide for ESM 6.8cProtect724gopi
 
ArcSight Connector Appliance v6.0 Release Notes
ArcSight Connector Appliance v6.0 Release NotesArcSight Connector Appliance v6.0 Release Notes
ArcSight Connector Appliance v6.0 Release NotesProtect724tk
 
Upgrading50 sp1or50sp2tov5.2
Upgrading50 sp1or50sp2tov5.2Upgrading50 sp1or50sp2tov5.2
Upgrading50 sp1or50sp2tov5.2Protect724
 
Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0	Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0 Protect724migration
 
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0Protect724v2
 
Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0	Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0 Protect724migration
 
Esm rel notes_6.0c
Esm rel notes_6.0cEsm rel notes_6.0c
Esm rel notes_6.0cProtect724
 
HPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release NotesHPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release Notesprotect724rkeer
 
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes	Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes Protect724manoj
 

Similar to ESM 6.8c Patch 2 Release Notes (19)

ArcSight Express 4.0 Virtual Appliance Guide
ArcSight Express 4.0 Virtual Appliance GuideArcSight Express 4.0 Virtual Appliance Guide
ArcSight Express 4.0 Virtual Appliance Guide
 
ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes	ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes
 
ESM 6.9.1c Release Notes
ESM 6.9.1c Release NotesESM 6.9.1c Release Notes
ESM 6.9.1c Release Notes
 
Esm rel notes_6.9.0
Esm rel notes_6.9.0Esm rel notes_6.9.0
Esm rel notes_6.9.0
 
ArcMC 2.6 Release Notes
ArcMC 2.6 Release NotesArcMC 2.6 Release Notes
ArcMC 2.6 Release Notes
 
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
 
Model Import Connector for RepSM Release Notes
Model Import Connector for RepSM Release NotesModel Import Connector for RepSM Release Notes
Model Import Connector for RepSM Release Notes
 
ArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release NotesArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release Notes
 
ESM_UpgradingTo5.6.pdf
ESM_UpgradingTo5.6.pdfESM_UpgradingTo5.6.pdf
ESM_UpgradingTo5.6.pdf
 
ArcSight Connector Appliance v6.1 Release Notes
ArcSight Connector Appliance v6.1 Release NotesArcSight Connector Appliance v6.1 Release Notes
ArcSight Connector Appliance v6.1 Release Notes
 
ESM Service Layer Developers Guide for ESM 6.8c
ESM Service Layer Developers Guide for ESM 6.8cESM Service Layer Developers Guide for ESM 6.8c
ESM Service Layer Developers Guide for ESM 6.8c
 
ArcSight Connector Appliance v6.0 Release Notes
ArcSight Connector Appliance v6.0 Release NotesArcSight Connector Appliance v6.0 Release Notes
ArcSight Connector Appliance v6.0 Release Notes
 
Upgrading50 sp1or50sp2tov5.2
Upgrading50 sp1or50sp2tov5.2Upgrading50 sp1or50sp2tov5.2
Upgrading50 sp1or50sp2tov5.2
 
Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0	Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0
 
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
 
Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0	Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0
 
Esm rel notes_6.0c
Esm rel notes_6.0cEsm rel notes_6.0c
Esm rel notes_6.0c
 
HPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release NotesHPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release Notes
 
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes	Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
 

More from Protect724v3

ArcSight EnterpriseView User Guide
ArcSight EnterpriseView User GuideArcSight EnterpriseView User Guide
ArcSight EnterpriseView User GuideProtect724v3
 
Release Notes for ESM 6.8c
Release Notes for ESM 6.8cRelease Notes for ESM 6.8c
Release Notes for ESM 6.8cProtect724v3
 
ESM5.6_SCG_Intrusion.pdf
ESM5.6_SCG_Intrusion.pdfESM5.6_SCG_Intrusion.pdf
ESM5.6_SCG_Intrusion.pdfProtect724v3
 
ArcSight Command Center User's Guide for ESM 6.8c
ArcSight Command Center User's Guide for ESM 6.8cArcSight Command Center User's Guide for ESM 6.8c
ArcSight Command Center User's Guide for ESM 6.8cProtect724v3
 
ESM5.6_SCG_NetFlow.pdf
ESM5.6_SCG_NetFlow.pdfESM5.6_SCG_NetFlow.pdf
ESM5.6_SCG_NetFlow.pdfProtect724v3
 
ESM Asset Model FlexConnector Developer's Guide for ESM 6.8c
ESM Asset Model FlexConnector Developer's Guide for ESM 6.8cESM Asset Model FlexConnector Developer's Guide for ESM 6.8c
ESM Asset Model FlexConnector Developer's Guide for ESM 6.8cProtect724v3
 
ESM5.6_SCG_Network.pdf
ESM5.6_SCG_Network.pdfESM5.6_SCG_Network.pdf
ESM5.6_SCG_Network.pdfProtect724v3
 
ESM5.6_SCG_Sys_Admin.pdf
ESM5.6_SCG_Sys_Admin.pdfESM5.6_SCG_Sys_Admin.pdf
ESM5.6_SCG_Sys_Admin.pdfProtect724v3
 
Arcsight ESM Support Matrix
Arcsight ESM Support MatrixArcsight ESM Support Matrix
Arcsight ESM Support MatrixProtect724v3
 
ESM5.6_SCG_Workflow.pdf
ESM5.6_SCG_Workflow.pdfESM5.6_SCG_Workflow.pdf
ESM5.6_SCG_Workflow.pdfProtect724v3
 
Event Data Transfer Tool 1.2 User's Guide
Event Data Transfer Tool 1.2 User's GuideEvent Data Transfer Tool 1.2 User's Guide
Event Data Transfer Tool 1.2 User's GuideProtect724v3
 
Esm event datatransfertool
Esm event datatransfertoolEsm event datatransfertool
Esm event datatransfertoolProtect724v3
 
Edtt rel notes_1.2
Edtt rel notes_1.2Edtt rel notes_1.2
Edtt rel notes_1.2Protect724v3
 
Esm support matrix
Esm support matrixEsm support matrix
Esm support matrixProtect724v3
 
Esm support matrix
Esm support matrixEsm support matrix
Esm support matrixProtect724v3
 
Esm support matrix_6.11.0 (1)
Esm support matrix_6.11.0 (1)Esm support matrix_6.11.0 (1)
Esm support matrix_6.11.0 (1)Protect724v3
 
Esm support matrix_6.11.0
Esm support matrix_6.11.0Esm support matrix_6.11.0
Esm support matrix_6.11.0Protect724v3
 
Esm scg net_flow_6.0c
Esm scg net_flow_6.0c Esm scg net_flow_6.0c
Esm scg net_flow_6.0c Protect724v3
 
Esm scg network_6.0c
Esm scg network_6.0cEsm scg network_6.0c
Esm scg network_6.0cProtect724v3
 

More from Protect724v3 (20)

ArcSight EnterpriseView User Guide
ArcSight EnterpriseView User GuideArcSight EnterpriseView User Guide
ArcSight EnterpriseView User Guide
 
Release Notes for ESM 6.8c
Release Notes for ESM 6.8cRelease Notes for ESM 6.8c
Release Notes for ESM 6.8c
 
ESM5.6_SCG_Intrusion.pdf
ESM5.6_SCG_Intrusion.pdfESM5.6_SCG_Intrusion.pdf
ESM5.6_SCG_Intrusion.pdf
 
ArcSight Command Center User's Guide for ESM 6.8c
ArcSight Command Center User's Guide for ESM 6.8cArcSight Command Center User's Guide for ESM 6.8c
ArcSight Command Center User's Guide for ESM 6.8c
 
ESM5.6_SCG_NetFlow.pdf
ESM5.6_SCG_NetFlow.pdfESM5.6_SCG_NetFlow.pdf
ESM5.6_SCG_NetFlow.pdf
 
ESM Asset Model FlexConnector Developer's Guide for ESM 6.8c
ESM Asset Model FlexConnector Developer's Guide for ESM 6.8cESM Asset Model FlexConnector Developer's Guide for ESM 6.8c
ESM Asset Model FlexConnector Developer's Guide for ESM 6.8c
 
ESM5.6_SCG_Network.pdf
ESM5.6_SCG_Network.pdfESM5.6_SCG_Network.pdf
ESM5.6_SCG_Network.pdf
 
ESM5.6_SCG_Sys_Admin.pdf
ESM5.6_SCG_Sys_Admin.pdfESM5.6_SCG_Sys_Admin.pdf
ESM5.6_SCG_Sys_Admin.pdf
 
Arcsight ESM Support Matrix
Arcsight ESM Support MatrixArcsight ESM Support Matrix
Arcsight ESM Support Matrix
 
ESM5.6_SCG_Workflow.pdf
ESM5.6_SCG_Workflow.pdfESM5.6_SCG_Workflow.pdf
ESM5.6_SCG_Workflow.pdf
 
Event Data Transfer Tool 1.2 User's Guide
Event Data Transfer Tool 1.2 User's GuideEvent Data Transfer Tool 1.2 User's Guide
Event Data Transfer Tool 1.2 User's Guide
 
Esm event datatransfertool
Esm event datatransfertoolEsm event datatransfertool
Esm event datatransfertool
 
Edtt rel notes_1.2
Edtt rel notes_1.2Edtt rel notes_1.2
Edtt rel notes_1.2
 
Esm support matrix
Esm support matrixEsm support matrix
Esm support matrix
 
Esm support matrix
Esm support matrixEsm support matrix
Esm support matrix
 
Esm support matrix_6.11.0 (1)
Esm support matrix_6.11.0 (1)Esm support matrix_6.11.0 (1)
Esm support matrix_6.11.0 (1)
 
Esm 101 5.2
Esm 101 5.2Esm 101 5.2
Esm 101 5.2
 
Esm support matrix_6.11.0
Esm support matrix_6.11.0Esm support matrix_6.11.0
Esm support matrix_6.11.0
 
Esm scg net_flow_6.0c
Esm scg net_flow_6.0c Esm scg net_flow_6.0c
Esm scg net_flow_6.0c
 
Esm scg network_6.0c
Esm scg network_6.0cEsm scg network_6.0c
Esm scg network_6.0c
 

Recently uploaded

Cloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEECloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEEVICTOR MAESTRE RAMIREZ
 
Asset Management Software - Infographic
Asset Management Software - InfographicAsset Management Software - Infographic
Asset Management Software - InfographicHr365.us smith
 
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)OPEN KNOWLEDGE GmbH
 
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWhat is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWave PLM
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfAlina Yurenko
 
The Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfThe Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfPower Karaoke
 
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASEBATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASEOrtus Solutions, Corp
 
Implementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureImplementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureDinusha Kumarasiri
 
Cloud Management Software Platforms: OpenStack
Cloud Management Software Platforms: OpenStackCloud Management Software Platforms: OpenStack
Cloud Management Software Platforms: OpenStackVICTOR MAESTRE RAMIREZ
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxTier1 app
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Andreas Granig
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanyChristoph Pohl
 
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...Christina Lin
 
EY_Graph Database Powered Sustainability
EY_Graph Database Powered SustainabilityEY_Graph Database Powered Sustainability
EY_Graph Database Powered SustainabilityNeo4j
 
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样umasea
 
Unveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New FeaturesUnveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New FeaturesŁukasz Chruściel
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based projectAnoyGreter
 
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataAdobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataBradBedford3
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio, Inc.
 
What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....kzayra69
 

Recently uploaded (20)

Cloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEECloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEE
 
Asset Management Software - Infographic
Asset Management Software - InfographicAsset Management Software - Infographic
Asset Management Software - Infographic
 
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)
 
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWhat is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need It
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
 
The Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdfThe Evolution of Karaoke From Analog to App.pdf
The Evolution of Karaoke From Analog to App.pdf
 
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASEBATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
BATTLEFIELD ORM: TIPS, TACTICS AND STRATEGIES FOR CONQUERING YOUR DATABASE
 
Implementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureImplementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with Azure
 
Cloud Management Software Platforms: OpenStack
Cloud Management Software Platforms: OpenStackCloud Management Software Platforms: OpenStack
Cloud Management Software Platforms: OpenStack
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
 
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
 
EY_Graph Database Powered Sustainability
EY_Graph Database Powered SustainabilityEY_Graph Database Powered Sustainability
EY_Graph Database Powered Sustainability
 
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
 
Unveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New FeaturesUnveiling the Future: Sylius 2.0 New Features
Unveiling the Future: Sylius 2.0 New Features
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based project
 
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataAdobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
 
What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....
 

ESM 6.8c Patch 2 Release Notes

  • 1. Release Notes ArcSight ESM Version 6.8c Patch 2 October 29, 2015
  • 2. Copyright © 2015 Hewlett-Packard Development Company, L.P. Confidential computer software. Valid license from HP required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. Follow this link to see a complete statement of copyrights and acknowledgements: http://www.hpenterprisesecurity.com/copyright Contact Information R Revision History Phone A list of phone numbers for HP ArcSight Technical Support is available on the HP Enterprise Security contacts page: https://softwaresupport.hp.com/documents/10180/14684/esp- support-contact-list Support Web Site http://softwaresupport.hp.com Protect 724 Community https://protect724.hp.com Date Product Version Description 10/29/2015 ArcSight ESM Version 6.8c Patch 2 Release Notes for ArcSight ESM Version 6.8c Patch 2.
  • 3. Confidential Release Notes ArcSight ESM 6.8c Patch 2 3 Contents ArcSight ESM Version 6.8c Patch 2 ......................................................................................................... 5 ESM 6.8c Patch 2 ............................................................................................................ 5 Purpose of this Patch ....................................................................................................... 5 Usage Notes for this Patch ................................................................................................ 5 Update Case Customizations in a Localized Environment ................................................ 5 ArcSight Web Configuration for PKCS#11/CAC .............................................................. 6 MSSP - Specific Settings ............................................................................................ 6 Section 508 Compliance ................................................................................................... 6 Geographical Information Update ...................................................................................... 6 Vulnerability Updates ....................................................................................................... 6 Installing ESM Version 6.8c Patch 2 ................................................................................... 7 Verify ESM 6.8c Patch 2 Files ...................................................................................... 9 ArcSight ESM Main Component Suite ........................................................................... 9 ArcSight Console ..................................................................................................... 11 Issues Fixed in this Patch ............................................................................................... 14 Analytics ................................................................................................................ 14 ArcSight Console ..................................................................................................... 14 ArcSight Manager .................................................................................................... 16 CORR-Engine .......................................................................................................... 16 Command Center .................................................................................................... 16 Open Issues in this Patch ............................................................................................... 18 ArcSight Console ..................................................................................................... 18 Installation and Upgrade .......................................................................................... 18 Issues Fixed in ESM 6.8c Patch 1 ..................................................................................... 18 Analytics ................................................................................................................ 18 ArcSight Console ..................................................................................................... 19 ArcSight Manager .................................................................................................... 19 CORR-Engine .......................................................................................................... 19 Command Center .................................................................................................... 19 Installation and Upgrade .......................................................................................... 19 Open and Closed Issues in ESM 6.8c ................................................................................ 20
  • 4. 4 Release Notes ArcSight ESM 6.8c Patch 2 Confidential Contents
  • 5. Confidential Release Notes ArcSight ESM 6.8c Patch 2 5 ArcSight ESM Version 6.8c Patch 2  ESM 6.8c Patch 2 These release notes describe how to apply this patch release of ArcSight ESM. Instructions are included for each component, as well as other information about recent changes and open and closed issues. This patch is for ArcSight ESM 6.8c only. To set up a new ESM 6.8c installation, refer to the ArcSight ESM Installation and Configuration Guide. The build number for the ESM suite for this patch is 1941. The build number for the ArcSight Console for this patch is 2108.2. After you have installed 6.8c, follow the instructions in “Installing ESM Version 6.8c Patch 2” on page 7 of these release notes to apply Patch 2. Purpose of this Patch This patch:  Addresses critical issues in ESM 6.8c; applicable to ESM 6.8c with or without ESM 6.8c patches.  Provides updates for geographical information and vulnerability mapping.  Provides important security updates.  Numerous Japanese language translation improvements  refer to the HP ArcSight ESM Support Matrix for the new and existing operating systems supported in this patch. Usage Notes for this Patch Refer to ArcSight ESM Release Notes for versions 6.8c. The usage notes for those releases also apply to this patch. Update Case Customizations in a Localized Environment When you install ESM 6.8c Patch 2, case customizations you made to the configuration are not preserved in the new installation. To regain your customizations, after installing ESM 6.8c Patch 2, copy the sections or lines having any case customizations in the Console and Manager <ARCSIGHT_HOME>i18ncommonlabel_strings_<locale>.properties and <ARCSIGHT_HOME>i18ncommonresource_strings_<locale>.properties files from the backup of your previous installation into those corresponding files in your current installation. Restart Manager and UI to see the customizations.
  • 6. Section 508 Compliance 6 Release Notes ArcSight ESM 6.8c Patch 2 Confidential ArcSight Web Configuration for PKCS#11/CAC These steps to configure PKCS#11/CAC for the ArcSight Web are not in the Installation Guide. To configure: 1 Import the CAC card’s root CA certificate into Web’s <ARCSIGHT_HOME>configjettywebtruststore directory. 2 Set ArcSight Web’s authentication to Password Based or SSL Client Based Authentication through webserversetup. For further details, see the ESM Administrator’s Guide. MSSP - Specific Settings In a managed security service provider (MSSP) environment, change the setting to disable the search auto-complete feature. To do this, in the logger.properties file change the value of auto-complete.fulltext.enabled to false and restart services. Section 508 Compliance ArcSight recognizes the importance of accessibility as a product initiative. To that end, ArcSight continues to make advances in the area of accessibility in its product lines. Geographical Information Update This version of ESM includes an update to the geographical information used in graphic displays. The version is GeoIP-532_20151001. Vulnerability Updates This release includes recent vulnerability mappings from the October 2015 Context Update. Device Vulnerability Updates Snort / Sourcefire SEU 1362 updated Faultline, Bugtraq, CVE, X-Force, Nessus Enterasys Dragon IDS updated CVE Cisco Secure IDS S888 updated CVE Juniper / Netscreen IDP update 2535 updated Faultline, Bugtraq, CVE, X-Force, Nessus, MSSB, CERT McAfee Intrushield 8.7.63.4 updated Faultline, Bugtraq, CVE, Nessus, X-Force, MSSB, CERT TippingPoint UnityOne DV8755 updated Faultline, Bugtraq, CVE, Nessus IBM Enterprise Scanner 1.137 updated CVE, X-Force IBM Security Host Protection for Desktops 3180 updated Faultline, CVE, Nessus, X-Force IBM Security Host Protection for Servers (Unix) 35.100 updated Faultline, CVE, Nessus, X-Force
  • 7. Installing ESM Version 6.8c Patch 2 Confidential Release Notes ArcSight ESM 6.8c Patch 2 7 Installing ESM Version 6.8c Patch 2 You can install this patch release using the platform-specific component executable files provided. Patch installers are available for all supported platforms. Please keep the following points in mind when installing Patch 2: Each component has install and uninstall steps. Verify ESM 6.8c Patch 2 Files HP provides a digital public key to enable you to verify that the signed software you received is indeed from HP and has not been manipulated in any way by a third party. Visit the following site for information and instructions: https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPL inuxCodeSigning IBM Security Host Protection for Servers (Windows) 3180 updated Faultline, CVE, Nessus, X-Force IBM Proventia Network IPS 35.100 updated Faultline, Bugtraq, CVE, Nessus, X-Force, MSSB IBM Proventia Network MFS 35.100 updated Faultline, Bugtraq, CVE, Nessus, X-Force, MSSB IBM Proventia Server IPS for Linux technology 35.100 updated Faultline, CVE, Nessus, X-Force IBM RealSecure Server Sensor XPU 35.100 updated Faultline, CVE, Nessus, X-Force McAfee HIPS 7.0/8.0 content version 6661 updated CVE • For all components and platforms: Make sure that you have enough space available before you install the patch. The installer checks for 1 GB of space and generates an error if it is not available. If you run into disk space issues during installation, create enough space, restore the component base build from the backup, then resume patch installation. • Backup, patch install, and uninstall procedures require permissions for the relevant components. To install a patch, make sure that the user who owns the base build installation folder has full privileges on the PATH where the base build is installed. • To uninstall the software you must be at the same user level as the original installer. • It is a good practice to create a backup of the existing product before installation begins. Do not simply rename files and leave them in the same directory. Java reads all the files present, regardless of renaming, and can pick up old code inadvertently, causing undesirable results. • For backup, patch install, and uninstall, we recommend that you log in to the target machine with a specific account name via telnet or SSH. If you switch accounts after logging in, then specify the flag "-" for the su command (su - <UserName>). Device Vulnerability Updates
  • 8. Installing ESM Version 6.8c Patch 2 8 Release Notes ArcSight ESM 6.8c Patch 2 Confidential ArcSight ESM Main Component Suite This section describes how to install or uninstall the ESM 6.8c Patch 2 for all the main components except the ArcSight Console. These components include the Manager, ArcSight Web, and the CORR-Engine. To Install the Patch 1 Download the patch from the HP Software Support Online site (http://softwaresupport.hp.com). ArcSightESMSuitePatch-XXXX.tar ...where XXXX represents the suite build number. Be sure to verify the patch file; see “Verify ESM 6.8c Patch 2 Files” on page 7. 2 As user arcsight, extract the tar file. 3 From the directory where you extracted the tar file, as user root, run stop_services with this command: ./stop_services.sh 4 Back up the ArcSight directory, /opt/arcsight, by making a copy. Place the copy in a readily accessible location. This is a precautionary measure so you can restore the system to the original state, if necessary. 5 Run the patch installer as user arcsight: ./ArcSightESMSuitePatch.bin To install in Console mode, run the following command from the shell prompt and then follow the instructions in the window: ./ArcSightESMSuitePatch.bin -i console 6 Read through the license agreement and accept it at the end. In GUI mode, the acceptance radio button is disabled until you scroll to the bottom of the agreement. In the console mode, press Enter until you have paged through to the end of the license agreement. 7 Select a location for the uninstaller link, if you want to have a shortcut to the uninstaller in some other location. You must have write permission to the specified folder. • Before you install the patch, verify that <ARCSIGHT_HOME> and any of its subdirectories are not being accessed by open shells on your system. • If for any reason you need to re-install the patch, run the patch uninstaller before installing the patch again. • HP recommends that you continue through the installation and do not attempt to cancel the installation process or move backward through the installer windows. HP recommends that you do not simply rename files and leave them in the same directory. Java reads all the files present, regardless of renaming, and can pick up old code inadvertently, causing undesirable results.
  • 9. Installing ESM Version 6.8c Patch 2 Confidential Release Notes ArcSight ESM 6.8c Patch 2 9 8 Check the pre-installation summary to verify that all the locations listed are correct and that you have enough disk space to install this patch. 9 Click Install. 10 Click Next on the File Delivery Complete screen to install the CORR-Engine, Manager, and ArcSight Web components. 11 Click Done on the Install Complete screen. 12 As root, run the runAsRoot script with this command: sh /opt/arcsight/suite/bin/runAsRoot.sh Messages will result from running this script; ignore the errors No such file or directory. Eventually, you will see the message: DONE: Set up ArcSight services. Services begin initializing after runAsRoot completes, but all services may take a short time to become fully available. 13 Check the ArcSight services as user arcsight: /etc/init.d/arcsight_services status all To Uninstall the Patch If needed, use the procedure below to uninstall this patch installation and restore the system to the pre-patched state. 1 As user root, run remove_services with this command: sh /opt/arcsight/manager/bin/remove_services.sh 2 As user arcsight, run the uninstaller program from either the directory where you created the link while installing the product or, if you had opted not to create a link, then run this from the /opt/arcsight/suitepatch_6.8.0.2/UninstallerData_6.8.0.2 directory: ./Uninstall_ArcSight_ESM_Suite_Patch Alternatively, you can run the following command from the /home/arcsight (or wherever you installed the shortcut link) directory: ./Uninstall_ArcSight_ESM_Suite_Patch_6.8.0.2 Or, to uninstall using Console mode, run: ./Uninstall_ArcSight_ESM_Suite_Patch_6.8.0.2 -i console Run the uninstaller in the same mode in which you ran the installer (GUI or Console mode). 3 Click Done on the Uninstall Complete screen. 4 As root, run setup_services with this command: sh /opt/arcsight/manager/bin/setup_services.sh Before you begin to uninstall, verify that the Manager’s <ARCSIGHT_HOME> and any of its subdirectories are not being accessed by any open shells on your system.
  • 10. Installing ESM Version 6.8c Patch 2 10 Release Notes ArcSight ESM 6.8c Patch 2 Confidential ArcSight Console This section describes how to install or uninstall the ESM 6.8c Patch 2 for ArcSight Console on Windows, Mac, and Linux platforms. To Install the Patch 1 Exit the ArcSight Console. 2 Back up the Console directory (for example, /home/arcsight/console/current) by making a copy. Place the copy in a readily accessible location. This is a precautionary measure so you can restore the original state, if necessary. 3 Download the executable file specific to your platform from the HP Software Support Online site (http://softwaresupport.hp.com). YYYY.Y represents the Console build number.  Patch-6.8.0.YYYY.Y-Console-Win.exe  Patch-6.8.0.YYYY.Y-Console-Linux.bin  Patch-6.8.0.YYYY.Y-Console-MacOSX.zip Be sure to verify the patch file; see “Verify ESM 6.8c Patch 2 Files” on page 7 For the Mac, see To Install the Patch on a Mac, below. 4 Run one of the following executables specific to your platform:  On Windows: Double-click Patch-6.8.0.YYYY.Y-Console-Win.exe  On Linux: Verify that you are logged in as user arcsight, and then run the following command: ./Patch-6.8.0.YYYY.Y-Console-Linux.bin The ArcSight ESM Console is not supported on AIX or Solaris. The following steps do not include information for installing a Console patch on those platforms. • Before you install the patch, verify that the Console’s <ARCSIGHT_HOME> directory and any of its subdirectories are not being accessed by any open shells on your system. • If you need to re-install the patch, run the patch uninstaller before installing the patch again. • HP recommends that you continue through the installation and do not attempt to cancel the installation process or move backward through the installer windows. HP recommends that you do not simply rename files and leave them in the same directory. Java reads all the files present, regardless of renaming, and can pick up old code inadvertently, causing undesirable results.
  • 11. Installing ESM Version 6.8c Patch 2 Confidential Release Notes ArcSight ESM 6.8c Patch 2 11 To install in Console mode, run the following command from the shell prompt and then follow the instructions in the window: ./Patch-6.8.0.YYYY.Y-Console-Linux.bin -i console The installer launches the Introduction window. 5 Read the instructions provided and click Next. 6 Accept the terms of the license agreement and click Next. The acceptance radio button is disabled until you scroll to the bottom of the agreement. 7 Enter the location of your existing <ARCSIGHT_HOME> directory for your Console installation in the text box provided or navigate to the location by clicking Choose… If you want to restore the installer-provided default location, click Restore Default Folder. 8 Click Next. 9 Choose a Link Location (on Linux) or Shortcut location (on Windows) by clicking the appropriate radio button and click Next. 10 Check the pre-installation summary to verify that all the locations listed are correct and that you have enough disk space to install this patch. 11 Click Install. 12 Click Done on the Install Complete screen. To Install the Patch on a Mac The patch installer download and run procedure is slightly different on the Mac than on the other supported platforms. 1 Exit the ArcSight Console. 2 Back up the Console directory (for example, /home/arcsight/console/current) by making a copy. Place the copy in a readily accessible location. This is just a precautionary measure so you can restore the original state, if necessary. 3 Download the file Patch-6.8.0.YYYY.Y-Console-MacOSX.zip to anywhere on your system. Be sure to verify the patch file; see “Verify ESM 6.8c Patch 2 Files” on page 7. 4 Launch the patch installer by double-clicking the ArcSightConsolePatch file. 5 Follow the steps on the patch install wizard, providing the information as prompted:  Accept the terms of the license agreement and click Next. The acceptance radio button is disabled until you scroll to the bottom of the agreement. HP recommends that you continue through the installation and do not attempt to cancel the installation process or move backward through the installer windows. The patch installer file shows as a ZIP file on the download site, but downloads as ArcSightConsolePatch.app on the Mac. A single or double-click on this APP file launches the patch installer, depending on how you have set these options. There is no need to “extract” or “unzip” the file; it downloads as an APP file.
  • 12. Installing ESM Version 6.8c Patch 2 12 Release Notes ArcSight ESM 6.8c Patch 2 Confidential  Choose the location where you want to install the patch. Browse to <ARCSIGHT_HOME>, where your previous Console was installed.  Choose an alias location for the Console application (or opt to not use aliases). This is the same as a link location on UNIX systems or shortcut location on Windows systems. 6 Click Next. 7 Verify your settings and click Install. To Uninstall the Patch If needed, use the procedure below to uninstall this patch installation. 1 Exit the ArcSight Console. 2 Run the uninstaller program: On Windows:  Double-click the icon you created for the uninstaller when installing the Console. For example, if you created an uninstaller icon on your desktop, double-click that icon.  If you created a link in the Start menu, click: Start > All Programs > ArcSight ESM Console 6.8c Patch 2 > Uninstall ArcSight ESM Console 6.8c Patch 2  Or, run the following from the Console’s <ARCSIGHT_HOME>currentUninstallerData_6.8.0.2 directory: Uninstall_ArcSight_ESM_Console_Patch  On Windows 8, run the following from the Console's <ARCSIGHT_HOME>currentUninstallerData_6.8.0.2 directory: Uninstall_ArcSight_ESM_Console_Patch.exe On Linux:  From the directory where you created the link when installing the Console (your home directory or some other location), run: ./Uninstall_ArcSight_ESM_Console_Patch_6.8.0.2  Or, to uninstall using Console mode, run: ./Uninstall_ArcSight_ESM_Console_Patch_6.8.0.2 -i console  If you did not create a link, execute the command from the Console’s <ARCSIGHT_HOME>/current/UninstallerData_6.8.0.2 directory: ./Uninstall_ArcSight_ESM_Console_Patch On a Mac:  From the directory where you created the link when installing the Console, run: Uninstall_ArcSight_ESM_Console_Patch_6.8.0.2 Before you begin to uninstall, verify that the Console’s <ARCSIGHT_HOME> and any of its subdirectories are not being accessed by any open shells on your system.
  • 13. Issues Fixed in this Patch Confidential Release Notes ArcSight ESM 6.8c Patch 2 13  From the Console’s <ARCSIGHT_HOME>/current/UninstallerData_6.8.0.2 directory, run: Uninstall_ArcSight_ESM_Console_Patch 3 Click Done on the Uninstall Complete screen. Issues Fixed in this Patch The following issues are fixed in this patch. Analytics ArcSight Console If you are on a Windows system and you plan to uninstall the base build Console after uninstalling Patch 2, be advised that your system restarts without warning upon finishing the base build uninstallation. Prepare your system accordingly. Issue Description NGS-14566 When a Query was constructed with a GROUP condition using 'Sum', SQL generation would fail. This issue is now fixed. Issue Description NGS-14933 "Bucket size in seconds" was not translated correctly into Japanese. This issue is now fixed. NGS-14791 Translations of "Required package For" and "Optional package For" were not correct for Japanese. This issue is now fixed. NGS-14723 In some cases, event-based Active Channels that include an InCase filtering condition do not display events that belong to a case but have been removed from the main event table (arc_event) due to the retention period limit. Case-related events are copied to a special table so they can remain available after being archived, but the channel is unable to find and display such events correctly after the partition is archived. Workaround: Use the case event editor or Reports, which can correctly find and display these events. NGS-14721 The “Moving Average" field in the Console Dashboard was translated incorrectly in Japanese. This issue is now fixed. NGS-14565 When case management was moved from ArcSight Web to ACC, the URL sent in email notifications was not updated correctly and still pointed to Web. This issue is now fixed. NGS-14525 Some archived reports that have Japanese characters in their names had garbled file names when downloaded, and the Japanese characters appeared blank. This issue is now fixed.
  • 14. Issues Fixed in this Patch 14 Release Notes ArcSight ESM 6.8c Patch 2 Confidential ArcSight Manager NGS-14522 The Console displayed some incorrect Japanese translations. • Login Console • Bucket size in Seconds • Number of Buckets Also, the following are not translated into Japanese: • The filtering being performed on the data monitor. • Bucket size in Seconds • Number of Buckets • Time Filed • The field to use for values • The file to aggregate data on This issue is now fixed. NGS-14503 When using dual monitors (multiple display), filter operators would sometimes display on the wrong monitor. This issue is now fixed. NGS-14483 Added support for a Static Banner at the top of every Console user interface connecting to a given Manager. To do this, set the server.staticbanner.backgroundcolor, server.staticbanner.textcolor and server.staticbanner.text properties in server.properties and restart the Manager. The backgroundcolor and textcolor properties only support the following color strings: black, blue, cyan, gray, green, magenta, orange, pink, red, white, yellow. If the server.staticbanner.text is not set or empty then banner panel will not display. If the server.staticbanner.backgroundcolor is invalid or is not set then default color green will be used. If the server.staticbanner.textcolor is invalid or is not set then the default color black will be used. NGS-12868 When using ArcSight Command Center to export a report to CSV format, if the field set contained agentReceiptTime, the value was always blank because the export mechanism expected the database field name instead of the display name. This issue is now fixed. Issue Description NGS-14567 The value size calculations for integer/long/double values were incorrect, which could result in errors saying "Event ... is too long for DB column size '19'." in server.log. This issue is now fixed. NGS-13222 Shutting down services by using the arcsight_services command might result in exceptions in the log file. These exceptions are due to an issue with the order in which the components are shut down, and can be safely ignored. NGS-13146 Shutting down services by using the arcsight_services command might result in exceptions in the log file. These exceptions are due to an issue with the order in which the components are shut down, and can be safely ignored. Issue Description
  • 15. Issues Fixed in this Patch Confidential Release Notes ArcSight ESM 6.8c Patch 2 15 CORR-Engine Command Center NGS-12225 Importing a CSV file into an active list with entries with the characters n, b, t, r (for example, C:usersrequests) causes the characters to appear erroneously in the ESM active list entry (e.g. C:usersrequests shows up as C:usersequests). Also, when this data is exported into a csv file, the data displays erroneously (n causes a newline space in the csv data). This issue is now fixed. NGS-10678 Under certain circumstances, an exception occurred during event processing which led to an EPS drop. This issue is now fixed. Issue Description NGS-14248 Filters using Target and Attacker User Name fields were not working as expected in active channels or reports when used with ignore case. This issue is now fixed. Issue Description NGS-14722 Some archive reports with PDF format that have been ran and saved through ArcSight Command Center couldn't be opened, and this error displays: Cannot Run Report. Possible reason it might be invalid or No access to Report Template or Query. This issue is now fixed. NGS-14525 Some archived reports that have Japanese characters in their names have garbled file names when downloaded, and the Japanese characters are shown as blank. This issue is now fixed. Issue Description
  • 16. Open Issues in this Patch 16 Release Notes ArcSight ESM 6.8c Patch 2 Confidential Open Issues in this Patch The following issues are open in this patch. ArcSight Console Installation and Upgrade Issues Fixed in ESM 6.8c Patch 1 The following issues are fixed in this patch. Analytics ArcSight Console Issue Description NGS-14853 On Windows, when uninstalling the base build after P2 has already been uninstalled, after you run the uninstaller program and click Done, the system restarts automatically. There is no prompt to let you choose whether to restart the system. Issue Description NGS-12870 On the Windows platform, after uninstalling ArcSight ESM Console patch 6.8.0.2, the UninstallerData_6.8.0.2 directory remains in the <Console/current> directory. This folder prevents ArcSight Console ESM patch 2 from installing again. Workaround: Delete ArcSight Console’s UninstallerData_6.8.0.2 directory. You can now re-install ArcSight Console ESM patch. Issue Description NGS-11107 Mapping certain Session List Global Variables (composed of multiple fields of different types) to a field with SetEventField action failed with errors. NGS-10996 "Export to External System" action on a rule did not work properly. NGS-9757 When a report included the "End Time" field, the time shown in that column was in the manager time zone instead of adjusted to the report query timezone. NGS-9505 If a rule contains an action to AddToActiveList, and the action (or the enclosing trigger) is disabled, exporting the rule to the package will not include the referenced ActiveList, because the dependency relationship is not stored correctly. Consequently, importing the package on another system (either manually or automatically via Content Sync) may result in the rule being marked invalid. Issue Description NGS-12752 When hotkeys were created for Profile Resources they did not work as expected.
  • 17. Issues Fixed in ESM 6.8c Patch 1 Confidential Release Notes ArcSight ESM 6.8c Patch 2 17 ArcSight Manager CORR-Engine Command Center Installation and Upgrade NGS-11515 Data Monitors did not remember column field positions after being saved. Issue Description NGS-11274 When using two consoles, in some conditions if the case information was edited in Console A, it was not replicated to Console B. NGS-11273 When using two consoles, in some conditions if the case information was edited in Console A, it was replicated to Console B immediately, but it was not replicated to Console A when the case was edited in Console B. NGS-11257 Prior to this fix, the password was not updated if it does not match the policy enforced (minimum length, previous password, etc.). The script would also silently fail meaning no error messages were displayed so the user would not know that the password was not updated. Issue Description NGS-13403 Case sensitive and insensitive queries sometimes returned wrong results when stored procedures or functions that return strings were used. Hence Active channels, Query Viewers and Reports gave wrong output when filtering events with and with out the Ignore Case option. Note that there is a limitation to this fix in Russian locale as the version of MySQL used in the product has limitations with Cyrillic characters. NGS-11262 Under certain circumstances, a Signal 11 crash could occur within mysqld. Issue Description NGS-13631 When a query involving "OR" was used on the ArcSight Command Center in a multi-tenant environment, customer-specific filtering failed. Issue Description NGS-11761 Issuing a 'arcsight_services stop' command when all services are down resulted in a failure 10 minutes later. NGS-9142 Under certain circumstances, arcsight_services would report inconsistent status alternating between "available" and "unavailable". Issue Description
  • 18. Open and Closed Issues in ESM 6.8c 18 Release Notes ArcSight ESM 6.8c Patch 2 Confidential Open and Closed Issues in ESM 6.8c For information about open and closed issues for ESM 6.8c, see the release notes for that version.