SlideShare a Scribd company logo
1 of 8
Download to read offline
HPE Security ArcSight Reputation
Security Monitor Plus
Software Version: 1.6
Release Notes
November 14, 2016
Legal Notices
Warranty
The only warranties for Hewlett Packard Enterprise products and services are set forth in the express warranty statements
accompanying such products and services. Nothing herein should be construed as constituting an additional warranty.
Hewlett Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein.
The information contained herein is subject to change without notice.
The network information used in the examples in this document (including IP addresses and hostnames) is for illustration
purposes only.
HPE Security ArcSight products are highly flexible and function as you configure them. The accessibility, integrity, and
confidentiality of your data is your responsibility. Implement a comprehensive security strategy and follow good security
practices.
This document is confidential.
Restricted Rights Legend
Confidential computer software. Valid license from Hewlett Packard Enterprise required for possession, use or copying.
Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical
Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license.
Copyright Notice
© Copyright 2016 Hewlett Packard Enterprise Development, LP
Follow this link to see a complete statement of copyrights and acknowledgements:
https://www.protect724.hpe.com/docs/DOC-13026
Support
Phone Alistof phone numbers is available on the HPE Security ArcSightTechnical Support
Page: https://softwaresupport.hpe.com/documents/10180/14684/esp-support-
contact-list
Support Web Site https://softwaresupport.hpe.com
Protect 724 Community https://www.protect724.hpe.com
Contact Information
Release Notes
HPE Reputation Security Monitor Plus 1.6 Page 2 of 8
Contents
Reputation Security Monitor Plus 1.6 4
How RepSM Plus Works 4
What's New in RepSM Plus 1.6 4
RepSM Plus Requirements 4
Release Contents 5
Installing RepSM Plus 5
Performance Impact of RepSM Plus 6
Open Issues 6
Send Documentation Feedback 8
HPE Reputation Security Monitor Plus 1.6 Page 3 of 8
Reputation Security Monitor Plus 1.6
How RepSM Plus Works
The Reputation Security Monitor Plus (RepSM Plus) solution uses internet threat intelligence to detect
malware infection, zero day attacks, and dangerous browsing on your network. RepSM Plus consists of
the following components:
l The HPE RepSM Plus service provides reputation data from the comprehensive database of
malicious IP addresses, host names, and domain names. The reputation database uses IPv4 and
Domain Name System (DNS) security intelligence feeds from multiple sources to provide a broad set
of reputation data.
l The HPE Model Import Connector for RepSM Plus imports the reputation data at regular intervals
from the RepSM Plus service to ArcSight ESM or ESM Express.
l The HPE RepSM Plus content running on ArcSight ESM or ESM Express correlates the reputation
data and security events to detect and remediate security incidents and issues that would otherwise
be undetectable. RepSM Plus content is organized into several use cases, which address specific
objectives.
For a complete overview of RepSM Plus, see the HPE Reputation Security Monitor Plus 1.6 Solution
Guide.
What's New in RepSM Plus 1.6
RepSM Plus 1.6 provides an updated version of the Model Import Connector for RepSM Plus. Refer to
the RepSM Plus Model Import Connector Guide for details.
The list of exploits has been expanded. Refer to the topic, "Exploit Types," in the RepSM Plus Solution
User's Guide for RepSM Plus 1.6.
Note: RepSM Plus 1.6 is available as a fresh installation only. Refer to the Support Matrix for a list of
current ESM versions. There are no upgrades from earlier versions of RepSM to this release.
RepSM Plus Requirements
l This release of RepSM Plus is supported on currently available versions of ESM, but only as fresh
installs. See the Solutions Support Matrix in Protect724 for more details.
HPE Reputation Security Monitor Plus 1.6 Page 4 of 8
l The ArcSight ESM Manager Java heap memory size must be set to at least 4 GB to support RepSM
Plus. If your Java heap memory size for Manager does not meet the requirements, see the ArcSight
ESM Administrator's Guide.
l RepSM Plus requires the Model Import Connector for RepSM Plus with an active subscription to the
RepSM Plus service. For additional connector requirements, see the Model Import Connector for
RepSM Plus Configuration Guide and accompanying release notes.
Release Contents
File Name Description
RepSM Plus Solution
Reputation_Security_Monitor_Plus_
1.6.arb
The installation package for all operating systems. Contains all the resources
for the RepSM Plus content package.
Note: Internet Explorer sometimes converts the ARB file to a ZIP file during
download. If this occurs, rename the ZIP file back to an ARB file before
importing into ArcSight ESM or ESM Express.
ESM_RepSM Plus_Solution_RelNotes_
1.6.pdf
The release notes (this document).
ESM_RepSM_Plus_SolutionGuide_
1.6.pdf
The HPE Security ArcSight Reputation Security Monitor 1.6 Solution Guide
provides product architecture, installation, configuration, and operation
instructions with a description of product contents.
Model Import Connector for RepSM Plus
ArcSight-7.3.0.7954.0-
RepSMModelConnector- Linux64.bin
ArcSight-7.3.0.7954.0-
RepSMModelConnector- Win64.exe
The installation executables for the Model Import Connector for RepSM Plus.
RepSMPlusModelImportConn_
RelNotes_7.3.0.7954.0.pdf
The Model Import Connector for RepSM Plus Release Notes provide a product
description and open issues.
RepSMPlusModelImportConn_
ConfigGuide_7.3.0.7954.0.pdf
The Model Import Connector for RepSM Plus Configuration Guide provides
information about installing and configuring the Model Import Connector for
RepSM Plus.
Installing RepSM Plus
For installation and configuration instructions, see the HPE Security ArcSight Reputation Security
Monitor Plus 1.6 Solution Guide.
Note that HPE provides a digital public key to enable you to verify that the signed software you
received is indeed from HPE and has not been manipulated in any way by a third party. Visit the
Release Notes
Reputation Security Monitor Plus 1.6
HPE Reputation Security Monitor Plus 1.6 Page 5 of 8
following site for information and instructions. Be sure to copy and paste the entire URL into a browser
to access the correct page:
https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPLinuxCode
Signing
Performance Impact of RepSM Plus
ArcSight solution content packages contain data monitors, trends, and rules that can place an
additional load on the ArcSight Manager and impact performance. If your ArcSight system is operating
at an average event per second (EPS) rate that has maximized the CPU utilization, you might
experience a reduced average EPS rate after installing the RepSM Plus package. If this performance
impact occurs, you can disable unneeded data monitors, trends, and rules to reduce the load on the
Manager.
Open Issues
Number Description
CON-12419 When restarting the Model Import Connector for RepSM Plus after it has been inactive for an
extended time, for example, more than a month, the connector retrieves all of the available
reputation data deltas at once, instead of retrieving a full update or only the appropriate
deltas.
Workaround: Restart the connector and perform a full import of the reputation data, as
described in the Model Import Connector for RepSM Plus Configuration Guide.
SOL-3606 Uninstalling RepSM Plus might fail with the following error:
Uninstall Failed: Unable to find resource with id 'kC85lx0BABCArD6yGhA5iA=='
Workaround: Restart the ArcSight Manager and then uninstall the RepSM Plus package.
SOL-3657 The Zero Day Attack Cases query viewer drilldowns do not show any data. The query viewer is
part of the Overview of Zero Day Attacks dashboard.
Workaround:
1. Edit the following query:
All Queries/ArcSight Solutions/Reputation Security Monitor 1.5/Zero Day Attacks/Summary
of Open Cases on Zero Day Attacks
2. On the Conditions tab, change the Group ID from:
0dRXhJTgBABCCLw7XLpNxFg==
to:
0MM5lXj0BABCBsT6yGhA5iA==
3. Save the query.
Release Notes
Reputation Security Monitor Plus 1.6
HPE Reputation Security Monitor Plus 1.6 Page 6 of 8
Number Description
SOL-3663 Installing RepSM Plus might fail with the following error:
Not enough privileges to modify All Drilldowns/Attachments/...
Workaround: Restart the ArcSight Manager and then install the RepSM Plus package.
SOL-3889 The /All Reports/ArcSight Solutions/Reputation Security Monitor Plus/General
Scenarios/Malicious Communication Trend over Time of the Last Day is supposed to run on
the last day; however the report configures and runs over the last seven days.
Workaround: Modify the time range manually. Right click the name of the report and select
Run > Report. In the Report Parameters dialog, change the Start Time custom parameter to
$Now - 1d and click OK.
SOL-3890 The /All Queries/ArcSight Solutions/Reputation Security Monitor Plus/General Scenarios/Layer
2 Events - Trend Base query description on the ArcSight Console states that the query
retrieves all Layer 2 events during the last hour.
This description is incorrect; the query retrieves all Layer 2 events during the last day.
Release Notes
Reputation Security Monitor Plus 1.6
HPE Reputation Security Monitor Plus 1.6 Page 7 of 8
Send Documentation Feedback
If you have comments about this document, you can contact the documentation team by email. If an
email client is configured on this system, click the link above and an email window opens with the
following information in the subject line:
Feedback on Release Notes (Reputation Security Monitor Plus 1.6)
Just add your feedback to the email and click send.
If no email client is available, copy the information above to a new message in a web mail client, and send
your feedback to arc-doc@hpe.com.
We appreciate your feedback!
HPE Reputation Security Monitor Plus 1.6 Page 8 of 8

More Related Content

What's hot

What's hot (20)

Upgrade ESM Express License to ESM 6.11.0
Upgrade ESM Express License to ESM 6.11.0Upgrade ESM Express License to ESM 6.11.0
Upgrade ESM Express License to ESM 6.11.0
 
Upgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8cUpgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8c
 
Anomalous Traffic Detection Security Use Case Guide
Anomalous Traffic Detection Security Use Case Guide	Anomalous Traffic Detection Security Use Case Guide
Anomalous Traffic Detection Security Use Case Guide
 
ESM_Express_InstallGuide_6.9.0.pdf
ESM_Express_InstallGuide_6.9.0.pdfESM_Express_InstallGuide_6.9.0.pdf
ESM_Express_InstallGuide_6.9.0.pdf
 
Suspicious Outbound Traffic Monitoring Security Use Case Guide
Suspicious Outbound Traffic Monitoring Security Use Case Guide	Suspicious Outbound Traffic Monitoring Security Use Case Guide
Suspicious Outbound Traffic Monitoring Security Use Case Guide
 
ESM 6.9.1c Patch 3 Release Notes
ESM 6.9.1c Patch 3 Release NotesESM 6.9.1c Patch 3 Release Notes
ESM 6.9.1c Patch 3 Release Notes
 
VPN Monitoring Security Use Case Guide version 1.1
VPN Monitoring Security Use Case Guide version 1.1	VPN Monitoring Security Use Case Guide version 1.1
VPN Monitoring Security Use Case Guide version 1.1
 
Paloalto Networks ACE
Paloalto Networks ACEPaloalto Networks ACE
Paloalto Networks ACE
 
Esm rel notes_6.8cp4
Esm rel notes_6.8cp4Esm rel notes_6.8cp4
Esm rel notes_6.8cp4
 
ESM 6.9.1c Patch 2 Release Notes
ESM 6.9.1c Patch 2 Release NotesESM 6.9.1c Patch 2 Release Notes
ESM 6.9.1c Patch 2 Release Notes
 
B7500 (G8) Upgrade to RHEL 6.8 (ESM 6.9.1c P2)
B7500 (G8) Upgrade to RHEL 6.8 (ESM 6.9.1c P2)B7500 (G8) Upgrade to RHEL 6.8 (ESM 6.9.1c P2)
B7500 (G8) Upgrade to RHEL 6.8 (ESM 6.9.1c P2)
 
Upgrading from ESM 5.0 SP2 or 5.2 to ESM 5.5
Upgrading from ESM 5.0 SP2 or 5.2 to ESM 5.5Upgrading from ESM 5.0 SP2 or 5.2 to ESM 5.5
Upgrading from ESM 5.0 SP2 or 5.2 to ESM 5.5
 
ESM_UpgradingTo5.6.pdf
ESM_UpgradingTo5.6.pdfESM_UpgradingTo5.6.pdf
ESM_UpgradingTo5.6.pdf
 
ArcSight Logger Forwarding Connector for HP Operations Manager
ArcSight Logger Forwarding Connector for HP Operations Manager	ArcSight Logger Forwarding Connector for HP Operations Manager
ArcSight Logger Forwarding Connector for HP Operations Manager
 
Logger Forwarding Connector for HPE OMi Configuration Guide 7.1.7.7610.0
Logger Forwarding Connector for HPE OMi Configuration Guide 7.1.7.7610.0	Logger Forwarding Connector for HPE OMi Configuration Guide 7.1.7.7610.0
Logger Forwarding Connector for HPE OMi Configuration Guide 7.1.7.7610.0
 
HPE InfoSight for 3PAR quickstart shortened v1
HPE InfoSight for 3PAR quickstart shortened v1HPE InfoSight for 3PAR quickstart shortened v1
HPE InfoSight for 3PAR quickstart shortened v1
 
Release Notes for ArcSight Express v4.0
Release Notes for ArcSight Express v4.0Release Notes for ArcSight Express v4.0
Release Notes for ArcSight Express v4.0
 
Cas 003-q&a-demo-exam area
Cas 003-q&a-demo-exam areaCas 003-q&a-demo-exam area
Cas 003-q&a-demo-exam area
 
OS Security Hardening for SAP HANA
OS Security Hardening for SAP HANAOS Security Hardening for SAP HANA
OS Security Hardening for SAP HANA
 
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes	Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
 

Similar to HPE ArcSight RepSM Plus 1.6 Release Notes

Similar to HPE ArcSight RepSM Plus 1.6 Release Notes (20)

HPE ArcSight RepSM Plus Model Import Connector Config Guide
HPE ArcSight RepSM Plus Model Import Connector Config GuideHPE ArcSight RepSM Plus Model Import Connector Config Guide
HPE ArcSight RepSM Plus Model Import Connector Config Guide
 
ESM 6.9.1c Patch1 Release Notes
	ESM 6.9.1c Patch1 Release Notes 	ESM 6.9.1c Patch1 Release Notes
ESM 6.9.1c Patch1 Release Notes
 
ESM Upgrade Guide (ESM v6.9.1c)
ESM Upgrade Guide (ESM v6.9.1c)ESM Upgrade Guide (ESM v6.9.1c)
ESM Upgrade Guide (ESM v6.9.1c)
 
NERC v6.0 for ESM Release Notes
NERC v6.0 for ESM Release NotesNERC v6.0 for ESM Release Notes
NERC v6.0 for ESM Release Notes
 
ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes	ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes
 
Model Import Connector for RepSM Release Notes
Model Import Connector for RepSM Release NotesModel Import Connector for RepSM Release Notes
Model Import Connector for RepSM Release Notes
 
ESM 6.5 Patch 1 Release Notes
ESM 6.5 Patch 1 Release NotesESM 6.5 Patch 1 Release Notes
ESM 6.5 Patch 1 Release Notes
 
Esm rel notes_6.9.0
Esm rel notes_6.9.0Esm rel notes_6.9.0
Esm rel notes_6.9.0
 
ESM 6.8 HA OS Upgrade from RHEL 6.5, 6.6, or 6.7 t..
ESM 6.8 HA OS Upgrade from RHEL 6.5, 6.6, or 6.7 t..ESM 6.8 HA OS Upgrade from RHEL 6.5, 6.6, or 6.7 t..
ESM 6.8 HA OS Upgrade from RHEL 6.5, 6.6, or 6.7 t..
 
Esm rel notes_6.0cp3
Esm rel notes_6.0cp3Esm rel notes_6.0cp3
Esm rel notes_6.0cp3
 
Deployment Guide for Risk_Insight 1.1
Deployment Guide for Risk_Insight 1.1Deployment Guide for Risk_Insight 1.1
Deployment Guide for Risk_Insight 1.1
 
Esm best practices_mssp
Esm best practices_msspEsm best practices_mssp
Esm best practices_mssp
 
ArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release NotesArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release Notes
 
ArcMC 2.6 Release Notes
ArcMC 2.6 Release NotesArcMC 2.6 Release Notes
ArcMC 2.6 Release Notes
 
Esm rel notes_6.0cp1
Esm rel notes_6.0cp1Esm rel notes_6.0cp1
Esm rel notes_6.0cp1
 
ESM 5.5 Patch 1 Release Notes
ESM 5.5 Patch 1 Release NotesESM 5.5 Patch 1 Release Notes
ESM 5.5 Patch 1 Release Notes
 
ESM 6.8c Patch 2 Release Notes
ESM 6.8c Patch 2 Release NotesESM 6.8c Patch 2 Release Notes
ESM 6.8c Patch 2 Release Notes
 
UPGRADING FROM ORACLE ENTERPRISE MANAGER 10G TO CLOUD CONTROL 12C WITH ZERO D...
UPGRADING FROM ORACLE ENTERPRISE MANAGER 10G TO CLOUD CONTROL 12C WITH ZERO D...UPGRADING FROM ORACLE ENTERPRISE MANAGER 10G TO CLOUD CONTROL 12C WITH ZERO D...
UPGRADING FROM ORACLE ENTERPRISE MANAGER 10G TO CLOUD CONTROL 12C WITH ZERO D...
 
ESM 6.9.1c Release Notes
ESM 6.9.1c Release NotesESM 6.9.1c Release Notes
ESM 6.9.1c Release Notes
 
Configuration Monitoring Standard Content Guide for ESM 6.8c
Configuration Monitoring Standard Content Guide for ESM 6.8cConfiguration Monitoring Standard Content Guide for ESM 6.8c
Configuration Monitoring Standard Content Guide for ESM 6.8c
 

More from protect724rkeer

More from protect724rkeer (14)

Actor Model Import Connector for Microsoft Active Directory
Actor Model Import Connector for Microsoft Active DirectoryActor Model Import Connector for Microsoft Active Directory
Actor Model Import Connector for Microsoft Active Directory
 
Actor Model Import Connector for Microsoft Active Directory Release Notes
Actor Model Import Connector for Microsoft Active Directory Release NotesActor Model Import Connector for Microsoft Active Directory Release Notes
Actor Model Import Connector for Microsoft Active Directory Release Notes
 
Actor Model Import FlexConnector for Database
Actor Model Import FlexConnector for DatabaseActor Model Import FlexConnector for Database
Actor Model Import FlexConnector for Database
 
Actor Model Import FlexConnector for Database Release Notes
Actor Model Import FlexConnector for Database Release NotesActor Model Import FlexConnector for Database Release Notes
Actor Model Import FlexConnector for Database Release Notes
 
CIP for PCI 4.0 Solution Guide for ArcSight Logger
CIP for PCI 4.0 Solution Guide for ArcSight LoggerCIP for PCI 4.0 Solution Guide for ArcSight Logger
CIP for PCI 4.0 Solution Guide for ArcSight Logger
 
CIP for PCI 4.0 Release Notes for ArcSight Logger
CIP for PCI 4.0 Release Notes for ArcSight LoggerCIP for PCI 4.0 Release Notes for ArcSight Logger
CIP for PCI 4.0 Release Notes for ArcSight Logger
 
CIP IT Governance 5.0 Solution Guide for ArcSight Logger
CIP IT Governance 5.0 Solution Guide for ArcSight LoggerCIP IT Governance 5.0 Solution Guide for ArcSight Logger
CIP IT Governance 5.0 Solution Guide for ArcSight Logger
 
CIP IT Governance 5.0 Release Notes for ArcSight Logger
CIP IT Governance 5.0 Release Notes for ArcSight LoggerCIP IT Governance 5.0 Release Notes for ArcSight Logger
CIP IT Governance 5.0 Release Notes for ArcSight Logger
 
Logger Brute Force Attack Detection Security Use Case User's Guide
Logger Brute Force Attack Detection Security Use Case User's GuideLogger Brute Force Attack Detection Security Use Case User's Guide
Logger Brute Force Attack Detection Security Use Case User's Guide
 
Logger NERC CIP 1.0 Solutions Guide
Logger NERC CIP 1.0 Solutions GuideLogger NERC CIP 1.0 Solutions Guide
Logger NERC CIP 1.0 Solutions Guide
 
Logger HIPAA CIP 1.0 Solutions Guide
Logger HIPAA CIP 1.0 Solutions GuideLogger HIPAA CIP 1.0 Solutions Guide
Logger HIPAA CIP 1.0 Solutions Guide
 
Logger NERC CIP 1.0 Release Notes
Logger NERC CIP 1.0 Release NotesLogger NERC CIP 1.0 Release Notes
Logger NERC CIP 1.0 Release Notes
 
Logger HIPAA CIP 1.0 Release Notes
Logger HIPAA CIP 1.0 Release NotesLogger HIPAA CIP 1.0 Release Notes
Logger HIPAA CIP 1.0 Release Notes
 
NERC v6.0 for ESM Solution Guide
NERC v6.0 for ESM Solution GuideNERC v6.0 for ESM Solution Guide
NERC v6.0 for ESM Solution Guide
 

Recently uploaded

AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
VictorSzoltysek
 
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdfintroduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
VishalKumarJha10
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 

Recently uploaded (20)

call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
Define the academic and professional writing..pdf
Define the academic and professional writing..pdfDefine the academic and professional writing..pdf
Define the academic and professional writing..pdf
 
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
Reassessing the Bedrock of Clinical Function Models: An Examination of Large ...
 
How To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.jsHow To Use Server-Side Rendering with Nuxt.js
How To Use Server-Side Rendering with Nuxt.js
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf
 
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
W01_panagenda_Navigating-the-Future-with-The-Hitchhikers-Guide-to-Notes-and-D...
 
10 Trends Likely to Shape Enterprise Technology in 2024
10 Trends Likely to Shape Enterprise Technology in 202410 Trends Likely to Shape Enterprise Technology in 2024
10 Trends Likely to Shape Enterprise Technology in 2024
 
Exploring the Best Video Editing App.pdf
Exploring the Best Video Editing App.pdfExploring the Best Video Editing App.pdf
Exploring the Best Video Editing App.pdf
 
Microsoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdfMicrosoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdf
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview Questions
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
 
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdfintroduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
introduction-to-automotive Andoid os-csimmonds-ndctechtown-2021.pdf
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 
8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students8257 interfacing 2 in microprocessor for btech students
8257 interfacing 2 in microprocessor for btech students
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
 
Unlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language ModelsUnlocking the Future of AI Agents with Large Language Models
Unlocking the Future of AI Agents with Large Language Models
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
Diamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with PrecisionDiamond Application Development Crafting Solutions with Precision
Diamond Application Development Crafting Solutions with Precision
 
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Pushp Vihar (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docx
 

HPE ArcSight RepSM Plus 1.6 Release Notes

  • 1. HPE Security ArcSight Reputation Security Monitor Plus Software Version: 1.6 Release Notes November 14, 2016
  • 2. Legal Notices Warranty The only warranties for Hewlett Packard Enterprise products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. Hewlett Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein. The information contained herein is subject to change without notice. The network information used in the examples in this document (including IP addresses and hostnames) is for illustration purposes only. HPE Security ArcSight products are highly flexible and function as you configure them. The accessibility, integrity, and confidentiality of your data is your responsibility. Implement a comprehensive security strategy and follow good security practices. This document is confidential. Restricted Rights Legend Confidential computer software. Valid license from Hewlett Packard Enterprise required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license. Copyright Notice © Copyright 2016 Hewlett Packard Enterprise Development, LP Follow this link to see a complete statement of copyrights and acknowledgements: https://www.protect724.hpe.com/docs/DOC-13026 Support Phone Alistof phone numbers is available on the HPE Security ArcSightTechnical Support Page: https://softwaresupport.hpe.com/documents/10180/14684/esp-support- contact-list Support Web Site https://softwaresupport.hpe.com Protect 724 Community https://www.protect724.hpe.com Contact Information Release Notes HPE Reputation Security Monitor Plus 1.6 Page 2 of 8
  • 3. Contents Reputation Security Monitor Plus 1.6 4 How RepSM Plus Works 4 What's New in RepSM Plus 1.6 4 RepSM Plus Requirements 4 Release Contents 5 Installing RepSM Plus 5 Performance Impact of RepSM Plus 6 Open Issues 6 Send Documentation Feedback 8 HPE Reputation Security Monitor Plus 1.6 Page 3 of 8
  • 4. Reputation Security Monitor Plus 1.6 How RepSM Plus Works The Reputation Security Monitor Plus (RepSM Plus) solution uses internet threat intelligence to detect malware infection, zero day attacks, and dangerous browsing on your network. RepSM Plus consists of the following components: l The HPE RepSM Plus service provides reputation data from the comprehensive database of malicious IP addresses, host names, and domain names. The reputation database uses IPv4 and Domain Name System (DNS) security intelligence feeds from multiple sources to provide a broad set of reputation data. l The HPE Model Import Connector for RepSM Plus imports the reputation data at regular intervals from the RepSM Plus service to ArcSight ESM or ESM Express. l The HPE RepSM Plus content running on ArcSight ESM or ESM Express correlates the reputation data and security events to detect and remediate security incidents and issues that would otherwise be undetectable. RepSM Plus content is organized into several use cases, which address specific objectives. For a complete overview of RepSM Plus, see the HPE Reputation Security Monitor Plus 1.6 Solution Guide. What's New in RepSM Plus 1.6 RepSM Plus 1.6 provides an updated version of the Model Import Connector for RepSM Plus. Refer to the RepSM Plus Model Import Connector Guide for details. The list of exploits has been expanded. Refer to the topic, "Exploit Types," in the RepSM Plus Solution User's Guide for RepSM Plus 1.6. Note: RepSM Plus 1.6 is available as a fresh installation only. Refer to the Support Matrix for a list of current ESM versions. There are no upgrades from earlier versions of RepSM to this release. RepSM Plus Requirements l This release of RepSM Plus is supported on currently available versions of ESM, but only as fresh installs. See the Solutions Support Matrix in Protect724 for more details. HPE Reputation Security Monitor Plus 1.6 Page 4 of 8
  • 5. l The ArcSight ESM Manager Java heap memory size must be set to at least 4 GB to support RepSM Plus. If your Java heap memory size for Manager does not meet the requirements, see the ArcSight ESM Administrator's Guide. l RepSM Plus requires the Model Import Connector for RepSM Plus with an active subscription to the RepSM Plus service. For additional connector requirements, see the Model Import Connector for RepSM Plus Configuration Guide and accompanying release notes. Release Contents File Name Description RepSM Plus Solution Reputation_Security_Monitor_Plus_ 1.6.arb The installation package for all operating systems. Contains all the resources for the RepSM Plus content package. Note: Internet Explorer sometimes converts the ARB file to a ZIP file during download. If this occurs, rename the ZIP file back to an ARB file before importing into ArcSight ESM or ESM Express. ESM_RepSM Plus_Solution_RelNotes_ 1.6.pdf The release notes (this document). ESM_RepSM_Plus_SolutionGuide_ 1.6.pdf The HPE Security ArcSight Reputation Security Monitor 1.6 Solution Guide provides product architecture, installation, configuration, and operation instructions with a description of product contents. Model Import Connector for RepSM Plus ArcSight-7.3.0.7954.0- RepSMModelConnector- Linux64.bin ArcSight-7.3.0.7954.0- RepSMModelConnector- Win64.exe The installation executables for the Model Import Connector for RepSM Plus. RepSMPlusModelImportConn_ RelNotes_7.3.0.7954.0.pdf The Model Import Connector for RepSM Plus Release Notes provide a product description and open issues. RepSMPlusModelImportConn_ ConfigGuide_7.3.0.7954.0.pdf The Model Import Connector for RepSM Plus Configuration Guide provides information about installing and configuring the Model Import Connector for RepSM Plus. Installing RepSM Plus For installation and configuration instructions, see the HPE Security ArcSight Reputation Security Monitor Plus 1.6 Solution Guide. Note that HPE provides a digital public key to enable you to verify that the signed software you received is indeed from HPE and has not been manipulated in any way by a third party. Visit the Release Notes Reputation Security Monitor Plus 1.6 HPE Reputation Security Monitor Plus 1.6 Page 5 of 8
  • 6. following site for information and instructions. Be sure to copy and paste the entire URL into a browser to access the correct page: https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPLinuxCode Signing Performance Impact of RepSM Plus ArcSight solution content packages contain data monitors, trends, and rules that can place an additional load on the ArcSight Manager and impact performance. If your ArcSight system is operating at an average event per second (EPS) rate that has maximized the CPU utilization, you might experience a reduced average EPS rate after installing the RepSM Plus package. If this performance impact occurs, you can disable unneeded data monitors, trends, and rules to reduce the load on the Manager. Open Issues Number Description CON-12419 When restarting the Model Import Connector for RepSM Plus after it has been inactive for an extended time, for example, more than a month, the connector retrieves all of the available reputation data deltas at once, instead of retrieving a full update or only the appropriate deltas. Workaround: Restart the connector and perform a full import of the reputation data, as described in the Model Import Connector for RepSM Plus Configuration Guide. SOL-3606 Uninstalling RepSM Plus might fail with the following error: Uninstall Failed: Unable to find resource with id 'kC85lx0BABCArD6yGhA5iA==' Workaround: Restart the ArcSight Manager and then uninstall the RepSM Plus package. SOL-3657 The Zero Day Attack Cases query viewer drilldowns do not show any data. The query viewer is part of the Overview of Zero Day Attacks dashboard. Workaround: 1. Edit the following query: All Queries/ArcSight Solutions/Reputation Security Monitor 1.5/Zero Day Attacks/Summary of Open Cases on Zero Day Attacks 2. On the Conditions tab, change the Group ID from: 0dRXhJTgBABCCLw7XLpNxFg== to: 0MM5lXj0BABCBsT6yGhA5iA== 3. Save the query. Release Notes Reputation Security Monitor Plus 1.6 HPE Reputation Security Monitor Plus 1.6 Page 6 of 8
  • 7. Number Description SOL-3663 Installing RepSM Plus might fail with the following error: Not enough privileges to modify All Drilldowns/Attachments/... Workaround: Restart the ArcSight Manager and then install the RepSM Plus package. SOL-3889 The /All Reports/ArcSight Solutions/Reputation Security Monitor Plus/General Scenarios/Malicious Communication Trend over Time of the Last Day is supposed to run on the last day; however the report configures and runs over the last seven days. Workaround: Modify the time range manually. Right click the name of the report and select Run > Report. In the Report Parameters dialog, change the Start Time custom parameter to $Now - 1d and click OK. SOL-3890 The /All Queries/ArcSight Solutions/Reputation Security Monitor Plus/General Scenarios/Layer 2 Events - Trend Base query description on the ArcSight Console states that the query retrieves all Layer 2 events during the last hour. This description is incorrect; the query retrieves all Layer 2 events during the last day. Release Notes Reputation Security Monitor Plus 1.6 HPE Reputation Security Monitor Plus 1.6 Page 7 of 8
  • 8. Send Documentation Feedback If you have comments about this document, you can contact the documentation team by email. If an email client is configured on this system, click the link above and an email window opens with the following information in the subject line: Feedback on Release Notes (Reputation Security Monitor Plus 1.6) Just add your feedback to the email and click send. If no email client is available, copy the information above to a new message in a web mail client, and send your feedback to arc-doc@hpe.com. We appreciate your feedback! HPE Reputation Security Monitor Plus 1.6 Page 8 of 8