More Related Content
Similar to TT3161_Afonin (20)
TT3161_Afonin
- 1. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
UsingHPArcSightAPIfordata
visualization
Eugene Afonin, Senior Sales Engineer
#HPProtect
- 2. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
SomeSIEMshavegooglemaps
integrations–couldwedobetter?
Plugginginopensourcetoolsfor
analytics
DoyouhaveaAppforthat?
Visualizedataonyourportal
- 3. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
SomeSIEMshavegooglemaps
integrations–couldwedobetter?
Plugginginopensourcetoolsfor
analytics
DoyouhaveaAppforthat?
Visualizedataonyourportal
- 4. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.4
Features - layout
Google Map
Events radar
Events details
- 5. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.5
Features - Google Map
Populated by events
details from the
clicked marker
Tooltip tells exact
numbers
Shows events
distribution by
priority
on marker click
- 6. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.6
Features - radar
Red – high priority
events, yellow –
medium and blue
are low
Hover mouse to
show tooltip
Each bar represent
one minute in the
event flow
Click here to
populate table with
corresponding
events
- 7. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.7
Features - table
Events count is
calculated
automatically for
each group level
Multiple grouping is
supported
To group events just
drag here any
column header
- 8. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.8
Features - table (cont)
Type here or click
any cell to filter on
cells values
Click to open/close
search filter
Click any column
header to sort
(asc/desc)
Type here or click
any cell to filter on
value
- 9. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.9
Features - clusters
Zoom level 2
Markers combine or split up according to the
map zoom level
Zoom level 4
- 10. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.10
How it works
Logger
*
*
*
ArcSight
ESM/Express
Logger search
API call
Search result
in JSON
Jscript code,
Jscript & chart
libraries
Google API,
Geo images
Visualization Web App
Incoming
events
High priority
events
- 11. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.11
APIs used
- 12. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.12
Could be enhanced
• Add filter input field – so the Logger search
query could be customized, not hardcoded
• Add status window – show applied filter, app
events etc.
• Allow user to set data refresh interval
• Make regular background JSON calls to silently
upload data from logger – no need to page
reload, hide search time lag from user
• Access rights
• Draw markers according to network model and show regional team details (email,
phone, shift timetable etc.)
• Ability to cluster events by customized map regions
• Calculate statistics by region
• Show different regions on different map zoom levels according to BUs or SOC team
structure
- 13. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
SomeSIEMshavegooglemaps
integrations–couldwedobetter?
Plugginginopensourcetoolsfor
analytics
DoyouhaveaAppforthat?
Visualizedataonyourportal
- 14. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.14
- 15. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.15
- 16. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.16
- 17. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.17
- 18. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
SomeSIEMshavegooglemaps
integrations–couldwedobetter?
Plugginginopensourcetoolsfor
analytics
DoyouhaveaAppforthat?
Visualizedataonyourportal
- 19. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.19
Gephi – open graph viz platform
Interactive visualization
and exploration platform
for all kinds of networks
and complex systems,
dynamic and hierarchical
graphs.
Runs on Windows, Linux
and Mac OS X. Gephi is
open-source and free.
- 20. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.20
HP ArcSight Interactive Discovery
- 21. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.21
HP ArcSight ESM / Express
Good: one shot –
one kill
Bad: AV can’t handle
- 22. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.22
Gephi – virus outbreak
Good: one shot –
one kill
Bad: AV can’t handle
Bad: Region creep
- 23. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.23
VIDEO STUB
- 24. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
- 25. © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.25
For more information
Attend these sessions
• TB3273, Practical Examples of Big Data, Security
Analytics and Visualization
• TT3139, An introduction to HP ArcSight ESM web
services APIs
• PN3578, Security analytics panel: Hunting bad guys
After the event
• Download sources at:
https://protect724.hp.com/
docs/DOC-11406
Your feedback is important to us.
Please take a few minutes to complete the session survey.