SlideShare a Scribd company logo
SmartConnector™
Configuration Guide for
ArcSight™ Logger Forwarding Connector for HP Operations
Manager
June, 2011
SmartConnectorTM
Guide for ArcSight™ Logger Forwarding Connector for HP Operations
Manager
Copyright © 2001-2011 ArcSight, LLC. All rights reserved.
ArcSight and the ArcSight logo are registered trademarks of ArcSight in the United States and in some other
countries. Where not registered, these marks and ArcSight Console, ArcSight ESM, ArcSight Express,
ArcSight Manager, ArcSight Web, ArcSight Enterprise View, FlexConnector, ArcSight FraudView, ArcSight
Identity View, ArcSight Interactive Discovery, ArcSight Logger, ArcSight NCM, SmartConnector, ArcSight
Threat Detector, ArcSight TRM, and ArcSight Viewer, are trademarks of ArcSight, LLC. All other brands,
products and company names used herein may be trademarks of their respective owners.
Follow this link to see a complete statement of ArcSight's copyrights, trademarks, and acknowledgements:
http://www.arcsight.com/copyrightnotice
The network information used in the examples in this document (including IP addresses and hostnames) is
for illustration purposes only.
This document is ArcSight Confidential.
Revision History
Release Notes template version: 2.1.0
ArcSight Customer Support
Date Description
06/2011 Second release of Logger Forwarding Connector for HP OM documentation.
05/2011 First release of Logger Forwarding Connector for HP OM documentation.
Phone 1-866-535-3285 (North America)
+44 (0)870 141 7487 (EMEA)
E-mail support@arcsight.com
Support Web Site http://www.arcsight.com/supportportal
Customer Forum https://forum.arcsight.com
ArcSight Confidential 3
Contents
Configuration Guide for Logger Forwarding Connector for HP OM .......................................................... 5
Supported Versions of HP OM ............................................................................................ 5
Sending Events From Logger to HP OM ............................................................................... 6
Installing the Connector ................................................................................................... 6
Logger Forwarders .......................................................................................................... 9
Creating a Forwarder to Forward Events ..................................................................... 10
Creating an SNMP Interceptor Policy ................................................................................ 11
Uploading Interceptor Template ................................................................................ 11
Using Operations Manager for Windows ...................................................................... 11
Using Operations Manager for UNIX or Linux ............................................................... 12
Deploying the Policy ................................................................................................ 12
Troubleshooting Tips ............................................................................................... 12
Duplicate Events ............................................................................................... 12
Dropped Events ................................................................................................ 12
Adjusting the Event Processing Rate ................................................................................ 13
4 ArcSight Confidential
ArcSight Confidential 5
Configuration Guide for Logger
Forwarding Connector for HP OM
This guide provides information on installing and configuring the Logger Forwarding
Connector for HP OM. This software supports Logger versions 5.0 and 5.1.
ArcSight Logger is a log management solution that is optimized for extremely high event
throughput, efficient long-term storage, and rapid data analysis. Logger receives and
stores events; supports search, retrieval, and reporting; and can forward selected
events.The ArcSight Logger Forwarding Connector allows you to send these event logs
from Logger to the HP Operations Manager (HP OM).
HP Operations Manager (HP OM) provides comprehensive event management,
proactive performance monitoring, and automated alerting, reporting, and graphing for
operating systems, middleware, and applications. It is designed to provide service-driven
event and performance management of business-critical enterprise systems, applications,
and services.
Supported Versions of HP OM
The supported versions of HP OM include
 HP OM for Windows v9.0 and 8.16 (patch level 90)
 HP OM for UNIX v9.10
 HP OM for Linux v9.10
“Supported Versions of HP OM” on page 5
“Sending Events From Logger to HP OM” on page 6
“Installing the Connector” on page 6
“Logger Forwarders” on page 9
“Creating an SNMP Interceptor Policy” on page 11
“Uploading Interceptor Template” on page 11
“Deploying the Policy” on page 12
“Troubleshooting Tips” on page 12
“Adjusting the Event Processing Rate” on page 13
Configuration Guide for Logger Forwarding Connector for OM
6 ArcSight Confidential
Sending Events From Logger to HP OM
ArcSight Logger sends events to the Logger Forwarding Connector using CEF Syslog, then
forwards the events to HP OM via SNMP. A Logger forwarder must be created to send these
events. For instructions on how to create a forwarder to send the events, see “Creating a
Forwarder to Forward Events” on page 10.
HP OM uses an SNMP interceptor policy to allow ArcSight events to be accepted within the
HP OM environment. For instructions on how to create an SNMP interceptor policy, see
“Creating an SNMP Interceptor Policy” on page 11.
Installing the Connector
Before you install the connector, make sure that the ArcSight products with which the
connectors will communicate have already been installed correctly (the ArcSight Logger, for
example) and you have assigned appropriate privileges. For data security, ArcSight
recommends that you install the connector and the HP Operations Agent on the same
system.
1 Download the ArcSight executable for your operating system from the ArcSight
Customer Support Site.
2 Start the ArcSight Installer by running the executable.
Follow the installation wizard through the following folder selection tasks and
installation of the core connector software:
Introduction
Choose Install Folder
Choose Install Set
Choose Shortcut Folder
Pre-Installation Summary
Installing...
3 The following destination window is displayed; click Next to continue.
Configuration Guide for Logger Forwarding Connector for OM
ArcSight Confidential 7
4 Fill in the parameter information required for connector configuration, then click Next.
Parameter Description
Host Enter the Host name or IP address of the HP OM
device. This is the HP OM managed node (the system
where the HP Operations Agent is installed, and to
which the SNMP interceptor policy is deployed).
Port Enter the port to be monitored for events by the HP
Operations Agent.
Version Accept the default value of SNMP_VERSION_2.
SNMP_VERSION_3 is not available at this time.
Read Community(v2) Enter the SNMP Read Community name.
Write Community(v2 Enter the SNMP Write Community name.
Authentication
Username(v3)
For use with SNMP v3; not available at this time.
Authentication Password(v3)
Security Level(v3)
Authentication Scheme(v3)
Privacy Password(v3)
Context Engine Id(v3)
Context name(v3)
Configuration Guide for Logger Forwarding Connector for OM
8 ArcSight Confidential
5 Click Logger to OM, then click Next.
6 Enter the Logger information, then click Next.
Parameter Description
Network Port 514 or another port that matches the Receiver
IP Address IP or host name of the Logger
Protocol UDP or Raw TCP
Note: Whichever protocol you choose, it must match
that of the forwarder type chosen during Logger
Forwarder configuration.
Configuration Guide for Logger Forwarding Connector for OM
ArcSight Confidential 9
7 Enter a name for the connector and provide other information identifying the
connector's use in your environment. Click Next.
8 Read the installation summary and click Next. If the summary is incorrect, click
Previous to make changes.
9 When the connector completes its configuration, click Next. The Wizard now prompts
you to choose whether you want to run the connector as a process or as a service.
If you choose to run the connector as a service, the Wizard prompts you to define
service parameters for the connector.
10 After making your selections, click Next. The Wizard displays a dialog confirming the
connector's setup and service configuration.
11 Click Finish.
12 Click Done.
Logger Forwarders
Logger forwarders allow you to send all events, or events which match a particular filter,
to another destination, in this instance, to HP OM. However, the ability to define a different
filter for each forwarder allows Logger to divide traffic among several destinations or limit
the events sent to a single destination. For example, because Logger can handle higher
event rates, it might be used to forward events to another HP OM management server
and/or an ArcSight ESM Manager. Forwarder query filters make it possible to split the flow
between the different devices, using one forwarder for each.
Logger forwarding uses several forwarder types, but the Logger Forwarding Connector
operates with UDP and TCP forwarder types only.
 UDP Forwarders forward events as User Datagram Protocol messages, such as
Syslog format datagrams.
 TCP Forwarders forward events as Transmission Control Protocol messages.
Configuration Guide for Logger Forwarding Connector for OM
10 ArcSight Confidential
Creating a Forwarder to Forward Events
In order to successfully forward events from Logger to HP OM, a forwarder must be
created. To do so, complete the following steps within the ArcSight Logger web application.
1 Click Configuration from the top-level menu bar.
2 Click Event Input/Output in the left panel.
3 Click the Forwarder tab, then click Add. The Add Forwarder page appears.
4 Enter a name for the new forwarder and choose either “UDP Forwarder” or “TCP
Forwarder”.
5 Click Next.
6 The Edit Forwarder page appears.
7 Within the Query field, create a query to filter the events sent to HP OM, or leave the
default, NONE, to send all events.
8 Continue to fill in the remaining parameters, ensuring that the Ip/Host field contains
the correct Logger Forwarding Connector IP address and that the Port number
matches that of the connector.
9 Click Save. The following page appears.
10 New forwarders are initially disabled, so click the disabled icon ( ) to enable the new
forwarder.
The forwarder is now enabled.
11 Start the Logger Forwarding Connector.
For more detailed information on Logger forwarders, see the ArcSight Logger
Administrator’s Guide.
Whichever forwarder type you choose, it must match that of the
SmartConnector protocol chosen during installation.
Wait a few minutes after enabling a forwarder before disabling it. Likewise,
wait before enabling a forwarder that has just been disabled. Background
tasks initiated by enabling or disabling a forwarder can produce unexpected
results if they are interrupted.
Configuration Guide for Logger Forwarding Connector for OM
ArcSight Confidential 11
Creating an SNMP Interceptor Policy
An SNMP interceptor policy is a type of HP OM policy, with rules, conditions, and actions.
Rules define what a policy should do in response to a specific type of event. Each rule
consists of a condition and an action. SNMP interceptor policies monitor SNMP events, and
can start actions when an SNMP event contains a specified character pattern. The Logger
Forwarding Connector sends security events as SNMP traps to an HP OM SNMP interceptor
policy that you will create.
SNMP interceptor policies can be configured on either HP OM UI, HP OM for Windows, or
HP OM for UNIX or Linux. ArcSight provides a template interceptor policy for use in
creating your own customized SNMP interceptor policy. This template policy should be
customized and enhanced to satisfy different needs and requirements with HP OM's
powerful policy edit features. You can upload the ArcSight SNMP interceptor policy
template to HP OM for Windows (using the ovpmutil command line tool) and to HP OM for
UNIX or Linux (using the opcpolicy command line tool).
Uploading Interceptor Template
After you have completed the connector installation, navigate to
$ARCSIGHT_HOMEcurrentuseragenthpompolicy. This folder provides policy
files as a basic SNMP interceptor template.
Using Operations Manager for Windows
Copy the hpompolicy folder from
$ARCSIGHT_HOMEcurrentuseragenthpompolicy to the destination HP OM for
Windows machine's C:temp directory. Then use the following command to upload the
policy:
"%OvBinDir%ovpmutil" CFG POL UPL "C:temphpompolicy"
You should receive the following messages:
Root policy group "for ArcSight Integration" uploading:
Policies upload completed successfully.
For descriptions of specific HP OM commands, refer to the HP Operations
Manager online help and documentation.
Configuration Guide for Logger Forwarding Connector for OM
12 ArcSight Confidential
Using Operations Manager for UNIX or Linux
Copy the hpompolicy folder from
$ARCSIGHT_HOMEcurrentuseragenthpompolicy to the destination HP OM
machine's /tmp directory. Then use the following command to upload the policy:
/opt/OV/bin/OpC/utils/opcpolicy -upload
dir=/tmp/hpompolicy/"ArcSight Events"
You should receive the following message:
Operation successfully completed.
Deploying the Policy
Once you have created your customized SNMP interceptor policy, deploy or assign the
policy through the HP OM for Windows or HP OM for UNIX or Linux Administration UI. For
details, refer to the HP Operations Manager online help and documentation.
The systems that send the SNMP traps to the logger must also be set up as nodes in HP
OM, because HP OM discards messages from unknown systems. Set up an external node or
an SNMP node. For details, refer to the HP Operations Manager online help and
documentation.
Also, configure the HP Operations Agent for SNMPv2 by setting the
SNMP_SESSION_MODE variable using the ovconfchg command line tool. Refer to the
HP Operations Manager or HP Operations Agent online help and documentation for more
information.
Troubleshooting Tips
Duplicate Events
If there appear to be duplicate events forwarded to the HP OM console:
1 Check and modify suppression options as needed.
2 If, after modifying suppression options, there still appear to be duplicate events, check
the Custom Message Attributes (event details and data), and apply rules to
differentiate the events.
Refer to the HP Operations Manager online help for details.
Dropped Events
If you notice that some events forwarded from ArcSight ESM/Logger are dropped, verify
whether the Agent Severity is set correctly in those events. The default SNMP interceptor
policy provided by ArcSight in the connector distribution has rules to pick up and forward
SNMP Traps from ArcSight ESM/Logger based on the Agent Severity. Events that do not
have Agent Severity set are dropped and not forwarded by the SNMP interceptor policy. If
the dropped events are correlated events from ESM, make sure that the rules on ESM are
set for the correct Agent Severity in the correlated events they generate. If the dropped
events are normalized events from devices, then verify that the originating connector that
For descriptions of specific HP OM commands, refer to the HP Operations
Manager online help and documentation.
Configuration Guide for Logger Forwarding Connector for OM
ArcSight Confidential 13
has normalized the event has mapped the Agent Severity correctly from the Device
Severity. If the originating connector (that is not setting the Agent Severity) is a
FlexConnector, review the mappings and map all of the device severities to one of these
Agent Severity values: Low, Medium, High, or Very-High. If the connector is a supported
connector, contact customer support.
Adjusting the Event Processing Rate
The default event processing rate for forwarding events from Logger to HP OM is 50 eps.
If this rate proves excessive for your system, HP OM may queue some incoming events and
affect the rate at which these events are processed.
If this occurs, you can adjust the rate at which events are forwarded to HP OM. To do so,
you will need to change the event processing rate within your XML properties file.
To adjust the event processing rate,
1 Stop the currently running SmartConnector from operating.
2 From a Windows command line, access your XML properties file using the command
cd %ARCSIGHT_HOME%/current/user/agent
3 Use WordPad or any XML Editor to open the .xml file for your HP OM destination,
similar to the example below:
0Ajv5S8BABCAAeabNXP5Rw==.xml
4 From within the .xml file, search for the following:
ProcessingSettings.ThrottleRate="50"
This value controls the current processing event rate, and has a default value of
50 eps.
5 Change this value to the desired rate of events per second. For example, to lower the
rate of events to 10 eps, change the value after the string to 10:
ProcessingSettings.ThrottleRate="10"
6 Save the .xml file and exit the XML editor.
7 Restart the SmartConnector.
If there are multiple destinations, repeat the steps above to change the
rate for each destination, as required.
Configuration Guide for Logger Forwarding Connector for OM
14 ArcSight Confidential

More Related Content

What's hot

Installation Guide for ESM 6.8c
Installation Guide for ESM 6.8cInstallation Guide for ESM 6.8c
Installation Guide for ESM 6.8c
Protect724migration
 
ClearPass Insight 6.3 User Guide
ClearPass Insight 6.3 User GuideClearPass Insight 6.3 User Guide
ClearPass Insight 6.3 User Guide
Aruba, a Hewlett Packard Enterprise company
 
ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081
ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081	ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081
ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081
Protect724manoj
 
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Protect724v2
 
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-EngineArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
Protect724
 
Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0	Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0
Protect724migration
 
Upgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8cUpgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8c
Protect724migration
 
ArcSight Management Center 2.2 Release Notes.pdf
ArcSight Management Center 2.2 Release Notes.pdfArcSight Management Center 2.2 Release Notes.pdf
ArcSight Management Center 2.2 Release Notes.pdf
Protect724mouni
 
ArcMC 2.6 Release Notes
ArcMC 2.6 Release NotesArcMC 2.6 Release Notes
ArcMC 2.6 Release Notes
Protect724mouni
 
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Protect724v2
 
Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0	Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0
Protect724migration
 
ArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release NotesArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release Notes
Protect724mouni
 
ClearPass 6.4.2 Release Notes
ClearPass 6.4.2 Release NotesClearPass 6.4.2 Release Notes
ClearPass 6.4.2 Release Notes
Aruba, a Hewlett Packard Enterprise company
 
HPE ArcSight RepSM Plus 1.6 Solution Guide
HPE ArcSight RepSM Plus 1.6 Solution GuideHPE ArcSight RepSM Plus 1.6 Solution Guide
HPE ArcSight RepSM Plus 1.6 Solution Guide
protect724rkeer
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authentication
dkaya
 
ArcSight Connector Appliance v6.0 Administrator's Guide
ArcSight Connector Appliance v6.0 Administrator's GuideArcSight Connector Appliance v6.0 Administrator's Guide
ArcSight Connector Appliance v6.0 Administrator's Guide
Protect724tk
 
ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes	ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes
Protect724mouni
 
HPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release NotesHPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release Notes
protect724rkeer
 
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Protect724v2
 

What's hot (20)

Installation Guide for ESM 6.8c
Installation Guide for ESM 6.8cInstallation Guide for ESM 6.8c
Installation Guide for ESM 6.8c
 
ClearPass Insight 6.3 User Guide
ClearPass Insight 6.3 User GuideClearPass Insight 6.3 User Guide
ClearPass Insight 6.3 User Guide
 
ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081
ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081	ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081
ArcSight Logger Forwarding Connector for HP NNMi Configuration Guide 5.1.7.6081
 
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
Forwarding Connector v5.2.7.6582.0 User's Guide for ArcSight Express v4.0
 
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-EngineArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
ArcSight Express Release Notes Version 3.0 featuring ESM + CORR-Engine
 
Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0	Forwarding Connector User's Guide for version 6.0.4.6830.0
Forwarding Connector User's Guide for version 6.0.4.6830.0
 
Upgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8cUpgrade Guide for ESM 6.8c
Upgrade Guide for ESM 6.8c
 
ArcSight Management Center 2.2 Release Notes.pdf
ArcSight Management Center 2.2 Release Notes.pdfArcSight Management Center 2.2 Release Notes.pdf
ArcSight Management Center 2.2 Release Notes.pdf
 
Aruba cppm 6_1_user_guide
Aruba cppm 6_1_user_guideAruba cppm 6_1_user_guide
Aruba cppm 6_1_user_guide
 
ArcMC 2.6 Release Notes
ArcMC 2.6 Release NotesArcMC 2.6 Release Notes
ArcMC 2.6 Release Notes
 
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
Reputation Security Monitor (RepSM) v1.01 Solution Guide for ArcSight Express...
 
Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0	Forwarding Connector Release Notes for version 6.0.4.6830.0
Forwarding Connector Release Notes for version 6.0.4.6830.0
 
ArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release NotesArcSight Management Center 2.5 Release Notes
ArcSight Management Center 2.5 Release Notes
 
ClearPass 6.4.2 Release Notes
ClearPass 6.4.2 Release NotesClearPass 6.4.2 Release Notes
ClearPass 6.4.2 Release Notes
 
HPE ArcSight RepSM Plus 1.6 Solution Guide
HPE ArcSight RepSM Plus 1.6 Solution GuideHPE ArcSight RepSM Plus 1.6 Solution Guide
HPE ArcSight RepSM Plus 1.6 Solution Guide
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authentication
 
ArcSight Connector Appliance v6.0 Administrator's Guide
ArcSight Connector Appliance v6.0 Administrator's GuideArcSight Connector Appliance v6.0 Administrator's Guide
ArcSight Connector Appliance v6.0 Administrator's Guide
 
ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes	ArcMC 2.5.1 Release Notes
ArcMC 2.5.1 Release Notes
 
HPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release NotesHPE ArcSight RepSM Plus 1.6 Release Notes
HPE ArcSight RepSM Plus 1.6 Release Notes
 
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
Reputation Security Monitor (RepSM) v1.01 Release Notes for ArcSight Express ...
 

Similar to ArcSight Logger Forwarding Connector for HP Operations Manager

ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079
ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079	ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079
ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079
Protect724manoj
 
Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0	Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0
Protect724manoj
 
ArcSight Logger Forwarding Connector for HP Network Node Manager i
ArcSight Logger Forwarding Connector for HP Network Node Manager i	ArcSight Logger Forwarding Connector for HP Network Node Manager i
ArcSight Logger Forwarding Connector for HP Network Node Manager i
Protect724manoj
 
Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide
Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide	Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide
Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide
Protect724manoj
 
Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide
Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide	Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide
Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide
Protect724manoj
 
Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0	Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0
Protect724manoj
 
FwdConn_ConfigGuide_7.1.3.7495.0.pdf
FwdConn_ConfigGuide_7.1.3.7495.0.pdfFwdConn_ConfigGuide_7.1.3.7495.0.pdf
FwdConn_ConfigGuide_7.1.3.7495.0.pdf
Protect724v2
 
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Protect724mouni
 
Forwarding Connector 7.1.7.7602.0 Configuration Guide
Forwarding Connector 7.1.7.7602.0 Configuration GuideForwarding Connector 7.1.7.7602.0 Configuration Guide
Forwarding Connector 7.1.7.7602.0 Configuration Guide
Protect724tk
 
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide	Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide
Protect724manoj
 
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes	Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes
Protect724manoj
 
Fwd conn configguide_5.2.5.6403.0
Fwd conn configguide_5.2.5.6403.0Fwd conn configguide_5.2.5.6403.0
Fwd conn configguide_5.2.5.6403.0
Protect724v3
 
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Protect724
 
Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154
Protect724
 
Asset Model Import FlexConnector Developer's Guide
Asset Model Import FlexConnector Developer's GuideAsset Model Import FlexConnector Developer's Guide
Asset Model Import FlexConnector Developer's Guide
Protect724migration
 
Smart Printing Technical Presentation
Smart Printing Technical PresentationSmart Printing Technical Presentation
Smart Printing Technical Presentation
JohnTileyITQ
 
RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...
RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...
RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...
Protect724v2
 
NetSim Technology Library - Software defined networks
NetSim Technology Library - Software defined networksNetSim Technology Library - Software defined networks
NetSim Technology Library - Software defined networks
Vishal Sharma
 
ESM Installation Guide (ESM v6.9.1c)
ESM Installation Guide (ESM v6.9.1c)ESM Installation Guide (ESM v6.9.1c)
ESM Installation Guide (ESM v6.9.1c)
Protect724tk
 

Similar to ArcSight Logger Forwarding Connector for HP Operations Manager (20)

ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079
ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079	ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079
ArcSight Logger Forwarding Connector for HP OM Configuration Guide 5.1.7.6079
 
Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0	Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Configuration Guide 7.1.7.7611.0
 
ArcSight Logger Forwarding Connector for HP Network Node Manager i
ArcSight Logger Forwarding Connector for HP Network Node Manager i	ArcSight Logger Forwarding Connector for HP Network Node Manager i
ArcSight Logger Forwarding Connector for HP Network Node Manager i
 
Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide
Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide	Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide
Logger Forwarding Connector for OM 7.3.0.7838.0 Configuration Guide
 
Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide
Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide	Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide
Logger Forwarding Connector for OMi 7.3.0.7839.0 Configuration Guide
 
Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0	Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Configuration Guide 7.1.7.7609.0
 
FwdConn_ConfigGuide_7.1.3.7495.0.pdf
FwdConn_ConfigGuide_7.1.3.7495.0.pdfFwdConn_ConfigGuide_7.1.3.7495.0.pdf
FwdConn_ConfigGuide_7.1.3.7495.0.pdf
 
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
Forwarding Connector 7.0.1.6992.0 User Guide for ESM 6.5c SP1
 
Forwarding Connector 7.1.7.7602.0 Configuration Guide
Forwarding Connector 7.1.7.7602.0 Configuration GuideForwarding Connector 7.1.7.7602.0 Configuration Guide
Forwarding Connector 7.1.7.7602.0 Configuration Guide
 
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide	Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Configuration Guide
 
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes	Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes
Logger Forwarding Connector for NNMi 7.3.0.7837.0 Release Notes
 
Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2
 
Fwd conn configguide_5.2.5.6403.0
Fwd conn configguide_5.2.5.6403.0Fwd conn configguide_5.2.5.6403.0
Fwd conn configguide_5.2.5.6403.0
 
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
Forwarding Connector User;s Guide for 5.1.7.6151 and 6154
 
Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154Fwd conn configguide_5.1.7.6151_6154
Fwd conn configguide_5.1.7.6151_6154
 
Asset Model Import FlexConnector Developer's Guide
Asset Model Import FlexConnector Developer's GuideAsset Model Import FlexConnector Developer's Guide
Asset Model Import FlexConnector Developer's Guide
 
Smart Printing Technical Presentation
Smart Printing Technical PresentationSmart Printing Technical Presentation
Smart Printing Technical Presentation
 
RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...
RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...
RepSM Model Import Connector v5.2.7.6581.0 Configuration Guide for ArcSight E...
 
NetSim Technology Library - Software defined networks
NetSim Technology Library - Software defined networksNetSim Technology Library - Software defined networks
NetSim Technology Library - Software defined networks
 
ESM Installation Guide (ESM v6.9.1c)
ESM Installation Guide (ESM v6.9.1c)ESM Installation Guide (ESM v6.9.1c)
ESM Installation Guide (ESM v6.9.1c)
 

More from Protect724manoj

Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0	Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0
Protect724manoj
 
Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0	Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0
Protect724manoj
 
Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610
Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610	Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610
Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610
Protect724manoj
 
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes	Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Protect724manoj
 
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes	Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
Protect724manoj
 
IDS - IPS Monitoring Security Use Case Guide
IDS - IPS Monitoring Security Use Case Guide	IDS - IPS Monitoring Security Use Case Guide
IDS - IPS Monitoring Security Use Case Guide
Protect724manoj
 
Firewall Monitoring 1.1 Security Use Case Guide
Firewall Monitoring 1.1 Security Use Case Guide	Firewall Monitoring 1.1 Security Use Case Guide
Firewall Monitoring 1.1 Security Use Case Guide
Protect724manoj
 
VPN Monitoring Security Use Case Guide version 1.1
VPN Monitoring Security Use Case Guide version 1.1	VPN Monitoring Security Use Case Guide version 1.1
VPN Monitoring Security Use Case Guide version 1.1
Protect724manoj
 
Suspicious Outbound Traffic Monitoring Security Use Case Guide
Suspicious Outbound Traffic Monitoring Security Use Case Guide	Suspicious Outbound Traffic Monitoring Security Use Case Guide
Suspicious Outbound Traffic Monitoring Security Use Case Guide
Protect724manoj
 
Anomalous Traffic Detection Security Use Case Guide
Anomalous Traffic Detection Security Use Case Guide	Anomalous Traffic Detection Security Use Case Guide
Anomalous Traffic Detection Security Use Case Guide
Protect724manoj
 
Brute Force Attack Security Use Case Guide
Brute Force Attack Security Use Case Guide	Brute Force Attack Security Use Case Guide
Brute Force Attack Security Use Case Guide
Protect724manoj
 
Reconnaissance Security Use Case
Reconnaissance Security Use Case	Reconnaissance Security Use Case
Reconnaissance Security Use Case
Protect724manoj
 
Antivirus Monitoring Security Use Case Guide
Antivirus Monitoring Security Use Case Guide	Antivirus Monitoring Security Use Case Guide
Antivirus Monitoring Security Use Case Guide
Protect724manoj
 
HPE ArcSight ESM Support Matrix
HPE ArcSight ESM Support Matrix	HPE ArcSight ESM Support Matrix
HPE ArcSight ESM Support Matrix
Protect724manoj
 

More from Protect724manoj (14)

Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0	Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0
Logger Forwarding Connector for HPE NNMi Release Notes 7.1.7.7609.0
 
Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0	Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0
Logger Forwarding Connector for HPE OM Release Notes 7.1.7.7611.0
 
Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610
Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610	Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610
Logger Forwarding Connector for HPE OMi Release Notes 7.1.7.7610
 
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes	Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
Logger Forwarding Connector for OM 7.3.0.7838.0 Release Notes
 
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes	Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
Logger Forwarding Connector for OMi 7.3.0.7839.0 Release Notes
 
IDS - IPS Monitoring Security Use Case Guide
IDS - IPS Monitoring Security Use Case Guide	IDS - IPS Monitoring Security Use Case Guide
IDS - IPS Monitoring Security Use Case Guide
 
Firewall Monitoring 1.1 Security Use Case Guide
Firewall Monitoring 1.1 Security Use Case Guide	Firewall Monitoring 1.1 Security Use Case Guide
Firewall Monitoring 1.1 Security Use Case Guide
 
VPN Monitoring Security Use Case Guide version 1.1
VPN Monitoring Security Use Case Guide version 1.1	VPN Monitoring Security Use Case Guide version 1.1
VPN Monitoring Security Use Case Guide version 1.1
 
Suspicious Outbound Traffic Monitoring Security Use Case Guide
Suspicious Outbound Traffic Monitoring Security Use Case Guide	Suspicious Outbound Traffic Monitoring Security Use Case Guide
Suspicious Outbound Traffic Monitoring Security Use Case Guide
 
Anomalous Traffic Detection Security Use Case Guide
Anomalous Traffic Detection Security Use Case Guide	Anomalous Traffic Detection Security Use Case Guide
Anomalous Traffic Detection Security Use Case Guide
 
Brute Force Attack Security Use Case Guide
Brute Force Attack Security Use Case Guide	Brute Force Attack Security Use Case Guide
Brute Force Attack Security Use Case Guide
 
Reconnaissance Security Use Case
Reconnaissance Security Use Case	Reconnaissance Security Use Case
Reconnaissance Security Use Case
 
Antivirus Monitoring Security Use Case Guide
Antivirus Monitoring Security Use Case Guide	Antivirus Monitoring Security Use Case Guide
Antivirus Monitoring Security Use Case Guide
 
HPE ArcSight ESM Support Matrix
HPE ArcSight ESM Support Matrix	HPE ArcSight ESM Support Matrix
HPE ArcSight ESM Support Matrix
 

Recently uploaded

Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
Donna Lenk
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus
 
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, BetterWebinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
XfilesPro
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
NYGGS Automation Suite
 
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.ILBeyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Natan Silnitsky
 
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
Juraj Vysvader
 
First Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User EndpointsFirst Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User Endpoints
Globus
 
2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx
Georgi Kodinov
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
Cyanic lab
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
abdulrafaychaudhry
 
Graphic Design Crash Course for beginners
Graphic Design Crash Course for beginnersGraphic Design Crash Course for beginners
Graphic Design Crash Course for beginners
e20449
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Shahin Sheidaei
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
Matt Welsh
 
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
takuyayamamoto1800
 
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Globus
 
Prosigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology SolutionsProsigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology Solutions
Prosigns
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
Paco van Beckhoven
 
GlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote sessionGlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote session
Globus
 
May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
Adele Miller
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus
 

Recently uploaded (20)

Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
 
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, BetterWebinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
 
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.ILBeyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
 
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
 
First Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User EndpointsFirst Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User Endpoints
 
2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx2024 RoOUG Security model for the cloud.pptx
2024 RoOUG Security model for the cloud.pptx
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
 
Graphic Design Crash Course for beginners
Graphic Design Crash Course for beginnersGraphic Design Crash Course for beginners
Graphic Design Crash Course for beginners
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
 
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoamOpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
OpenFOAM solver for Helmholtz equation, helmholtzFoam / helmholtzBubbleFoam
 
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
Exploring Innovations in Data Repository Solutions - Insights from the U.S. G...
 
Prosigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology SolutionsProsigns: Transforming Business with Tailored Technology Solutions
Prosigns: Transforming Business with Tailored Technology Solutions
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
 
GlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote sessionGlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote session
 
May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
 

ArcSight Logger Forwarding Connector for HP Operations Manager

  • 1. SmartConnector™ Configuration Guide for ArcSight™ Logger Forwarding Connector for HP Operations Manager June, 2011
  • 2. SmartConnectorTM Guide for ArcSight™ Logger Forwarding Connector for HP Operations Manager Copyright © 2001-2011 ArcSight, LLC. All rights reserved. ArcSight and the ArcSight logo are registered trademarks of ArcSight in the United States and in some other countries. Where not registered, these marks and ArcSight Console, ArcSight ESM, ArcSight Express, ArcSight Manager, ArcSight Web, ArcSight Enterprise View, FlexConnector, ArcSight FraudView, ArcSight Identity View, ArcSight Interactive Discovery, ArcSight Logger, ArcSight NCM, SmartConnector, ArcSight Threat Detector, ArcSight TRM, and ArcSight Viewer, are trademarks of ArcSight, LLC. All other brands, products and company names used herein may be trademarks of their respective owners. Follow this link to see a complete statement of ArcSight's copyrights, trademarks, and acknowledgements: http://www.arcsight.com/copyrightnotice The network information used in the examples in this document (including IP addresses and hostnames) is for illustration purposes only. This document is ArcSight Confidential. Revision History Release Notes template version: 2.1.0 ArcSight Customer Support Date Description 06/2011 Second release of Logger Forwarding Connector for HP OM documentation. 05/2011 First release of Logger Forwarding Connector for HP OM documentation. Phone 1-866-535-3285 (North America) +44 (0)870 141 7487 (EMEA) E-mail support@arcsight.com Support Web Site http://www.arcsight.com/supportportal Customer Forum https://forum.arcsight.com
  • 3. ArcSight Confidential 3 Contents Configuration Guide for Logger Forwarding Connector for HP OM .......................................................... 5 Supported Versions of HP OM ............................................................................................ 5 Sending Events From Logger to HP OM ............................................................................... 6 Installing the Connector ................................................................................................... 6 Logger Forwarders .......................................................................................................... 9 Creating a Forwarder to Forward Events ..................................................................... 10 Creating an SNMP Interceptor Policy ................................................................................ 11 Uploading Interceptor Template ................................................................................ 11 Using Operations Manager for Windows ...................................................................... 11 Using Operations Manager for UNIX or Linux ............................................................... 12 Deploying the Policy ................................................................................................ 12 Troubleshooting Tips ............................................................................................... 12 Duplicate Events ............................................................................................... 12 Dropped Events ................................................................................................ 12 Adjusting the Event Processing Rate ................................................................................ 13
  • 5. ArcSight Confidential 5 Configuration Guide for Logger Forwarding Connector for HP OM This guide provides information on installing and configuring the Logger Forwarding Connector for HP OM. This software supports Logger versions 5.0 and 5.1. ArcSight Logger is a log management solution that is optimized for extremely high event throughput, efficient long-term storage, and rapid data analysis. Logger receives and stores events; supports search, retrieval, and reporting; and can forward selected events.The ArcSight Logger Forwarding Connector allows you to send these event logs from Logger to the HP Operations Manager (HP OM). HP Operations Manager (HP OM) provides comprehensive event management, proactive performance monitoring, and automated alerting, reporting, and graphing for operating systems, middleware, and applications. It is designed to provide service-driven event and performance management of business-critical enterprise systems, applications, and services. Supported Versions of HP OM The supported versions of HP OM include  HP OM for Windows v9.0 and 8.16 (patch level 90)  HP OM for UNIX v9.10  HP OM for Linux v9.10 “Supported Versions of HP OM” on page 5 “Sending Events From Logger to HP OM” on page 6 “Installing the Connector” on page 6 “Logger Forwarders” on page 9 “Creating an SNMP Interceptor Policy” on page 11 “Uploading Interceptor Template” on page 11 “Deploying the Policy” on page 12 “Troubleshooting Tips” on page 12 “Adjusting the Event Processing Rate” on page 13
  • 6. Configuration Guide for Logger Forwarding Connector for OM 6 ArcSight Confidential Sending Events From Logger to HP OM ArcSight Logger sends events to the Logger Forwarding Connector using CEF Syslog, then forwards the events to HP OM via SNMP. A Logger forwarder must be created to send these events. For instructions on how to create a forwarder to send the events, see “Creating a Forwarder to Forward Events” on page 10. HP OM uses an SNMP interceptor policy to allow ArcSight events to be accepted within the HP OM environment. For instructions on how to create an SNMP interceptor policy, see “Creating an SNMP Interceptor Policy” on page 11. Installing the Connector Before you install the connector, make sure that the ArcSight products with which the connectors will communicate have already been installed correctly (the ArcSight Logger, for example) and you have assigned appropriate privileges. For data security, ArcSight recommends that you install the connector and the HP Operations Agent on the same system. 1 Download the ArcSight executable for your operating system from the ArcSight Customer Support Site. 2 Start the ArcSight Installer by running the executable. Follow the installation wizard through the following folder selection tasks and installation of the core connector software: Introduction Choose Install Folder Choose Install Set Choose Shortcut Folder Pre-Installation Summary Installing... 3 The following destination window is displayed; click Next to continue.
  • 7. Configuration Guide for Logger Forwarding Connector for OM ArcSight Confidential 7 4 Fill in the parameter information required for connector configuration, then click Next. Parameter Description Host Enter the Host name or IP address of the HP OM device. This is the HP OM managed node (the system where the HP Operations Agent is installed, and to which the SNMP interceptor policy is deployed). Port Enter the port to be monitored for events by the HP Operations Agent. Version Accept the default value of SNMP_VERSION_2. SNMP_VERSION_3 is not available at this time. Read Community(v2) Enter the SNMP Read Community name. Write Community(v2 Enter the SNMP Write Community name. Authentication Username(v3) For use with SNMP v3; not available at this time. Authentication Password(v3) Security Level(v3) Authentication Scheme(v3) Privacy Password(v3) Context Engine Id(v3) Context name(v3)
  • 8. Configuration Guide for Logger Forwarding Connector for OM 8 ArcSight Confidential 5 Click Logger to OM, then click Next. 6 Enter the Logger information, then click Next. Parameter Description Network Port 514 or another port that matches the Receiver IP Address IP or host name of the Logger Protocol UDP or Raw TCP Note: Whichever protocol you choose, it must match that of the forwarder type chosen during Logger Forwarder configuration.
  • 9. Configuration Guide for Logger Forwarding Connector for OM ArcSight Confidential 9 7 Enter a name for the connector and provide other information identifying the connector's use in your environment. Click Next. 8 Read the installation summary and click Next. If the summary is incorrect, click Previous to make changes. 9 When the connector completes its configuration, click Next. The Wizard now prompts you to choose whether you want to run the connector as a process or as a service. If you choose to run the connector as a service, the Wizard prompts you to define service parameters for the connector. 10 After making your selections, click Next. The Wizard displays a dialog confirming the connector's setup and service configuration. 11 Click Finish. 12 Click Done. Logger Forwarders Logger forwarders allow you to send all events, or events which match a particular filter, to another destination, in this instance, to HP OM. However, the ability to define a different filter for each forwarder allows Logger to divide traffic among several destinations or limit the events sent to a single destination. For example, because Logger can handle higher event rates, it might be used to forward events to another HP OM management server and/or an ArcSight ESM Manager. Forwarder query filters make it possible to split the flow between the different devices, using one forwarder for each. Logger forwarding uses several forwarder types, but the Logger Forwarding Connector operates with UDP and TCP forwarder types only.  UDP Forwarders forward events as User Datagram Protocol messages, such as Syslog format datagrams.  TCP Forwarders forward events as Transmission Control Protocol messages.
  • 10. Configuration Guide for Logger Forwarding Connector for OM 10 ArcSight Confidential Creating a Forwarder to Forward Events In order to successfully forward events from Logger to HP OM, a forwarder must be created. To do so, complete the following steps within the ArcSight Logger web application. 1 Click Configuration from the top-level menu bar. 2 Click Event Input/Output in the left panel. 3 Click the Forwarder tab, then click Add. The Add Forwarder page appears. 4 Enter a name for the new forwarder and choose either “UDP Forwarder” or “TCP Forwarder”. 5 Click Next. 6 The Edit Forwarder page appears. 7 Within the Query field, create a query to filter the events sent to HP OM, or leave the default, NONE, to send all events. 8 Continue to fill in the remaining parameters, ensuring that the Ip/Host field contains the correct Logger Forwarding Connector IP address and that the Port number matches that of the connector. 9 Click Save. The following page appears. 10 New forwarders are initially disabled, so click the disabled icon ( ) to enable the new forwarder. The forwarder is now enabled. 11 Start the Logger Forwarding Connector. For more detailed information on Logger forwarders, see the ArcSight Logger Administrator’s Guide. Whichever forwarder type you choose, it must match that of the SmartConnector protocol chosen during installation. Wait a few minutes after enabling a forwarder before disabling it. Likewise, wait before enabling a forwarder that has just been disabled. Background tasks initiated by enabling or disabling a forwarder can produce unexpected results if they are interrupted.
  • 11. Configuration Guide for Logger Forwarding Connector for OM ArcSight Confidential 11 Creating an SNMP Interceptor Policy An SNMP interceptor policy is a type of HP OM policy, with rules, conditions, and actions. Rules define what a policy should do in response to a specific type of event. Each rule consists of a condition and an action. SNMP interceptor policies monitor SNMP events, and can start actions when an SNMP event contains a specified character pattern. The Logger Forwarding Connector sends security events as SNMP traps to an HP OM SNMP interceptor policy that you will create. SNMP interceptor policies can be configured on either HP OM UI, HP OM for Windows, or HP OM for UNIX or Linux. ArcSight provides a template interceptor policy for use in creating your own customized SNMP interceptor policy. This template policy should be customized and enhanced to satisfy different needs and requirements with HP OM's powerful policy edit features. You can upload the ArcSight SNMP interceptor policy template to HP OM for Windows (using the ovpmutil command line tool) and to HP OM for UNIX or Linux (using the opcpolicy command line tool). Uploading Interceptor Template After you have completed the connector installation, navigate to $ARCSIGHT_HOMEcurrentuseragenthpompolicy. This folder provides policy files as a basic SNMP interceptor template. Using Operations Manager for Windows Copy the hpompolicy folder from $ARCSIGHT_HOMEcurrentuseragenthpompolicy to the destination HP OM for Windows machine's C:temp directory. Then use the following command to upload the policy: "%OvBinDir%ovpmutil" CFG POL UPL "C:temphpompolicy" You should receive the following messages: Root policy group "for ArcSight Integration" uploading: Policies upload completed successfully. For descriptions of specific HP OM commands, refer to the HP Operations Manager online help and documentation.
  • 12. Configuration Guide for Logger Forwarding Connector for OM 12 ArcSight Confidential Using Operations Manager for UNIX or Linux Copy the hpompolicy folder from $ARCSIGHT_HOMEcurrentuseragenthpompolicy to the destination HP OM machine's /tmp directory. Then use the following command to upload the policy: /opt/OV/bin/OpC/utils/opcpolicy -upload dir=/tmp/hpompolicy/"ArcSight Events" You should receive the following message: Operation successfully completed. Deploying the Policy Once you have created your customized SNMP interceptor policy, deploy or assign the policy through the HP OM for Windows or HP OM for UNIX or Linux Administration UI. For details, refer to the HP Operations Manager online help and documentation. The systems that send the SNMP traps to the logger must also be set up as nodes in HP OM, because HP OM discards messages from unknown systems. Set up an external node or an SNMP node. For details, refer to the HP Operations Manager online help and documentation. Also, configure the HP Operations Agent for SNMPv2 by setting the SNMP_SESSION_MODE variable using the ovconfchg command line tool. Refer to the HP Operations Manager or HP Operations Agent online help and documentation for more information. Troubleshooting Tips Duplicate Events If there appear to be duplicate events forwarded to the HP OM console: 1 Check and modify suppression options as needed. 2 If, after modifying suppression options, there still appear to be duplicate events, check the Custom Message Attributes (event details and data), and apply rules to differentiate the events. Refer to the HP Operations Manager online help for details. Dropped Events If you notice that some events forwarded from ArcSight ESM/Logger are dropped, verify whether the Agent Severity is set correctly in those events. The default SNMP interceptor policy provided by ArcSight in the connector distribution has rules to pick up and forward SNMP Traps from ArcSight ESM/Logger based on the Agent Severity. Events that do not have Agent Severity set are dropped and not forwarded by the SNMP interceptor policy. If the dropped events are correlated events from ESM, make sure that the rules on ESM are set for the correct Agent Severity in the correlated events they generate. If the dropped events are normalized events from devices, then verify that the originating connector that For descriptions of specific HP OM commands, refer to the HP Operations Manager online help and documentation.
  • 13. Configuration Guide for Logger Forwarding Connector for OM ArcSight Confidential 13 has normalized the event has mapped the Agent Severity correctly from the Device Severity. If the originating connector (that is not setting the Agent Severity) is a FlexConnector, review the mappings and map all of the device severities to one of these Agent Severity values: Low, Medium, High, or Very-High. If the connector is a supported connector, contact customer support. Adjusting the Event Processing Rate The default event processing rate for forwarding events from Logger to HP OM is 50 eps. If this rate proves excessive for your system, HP OM may queue some incoming events and affect the rate at which these events are processed. If this occurs, you can adjust the rate at which events are forwarded to HP OM. To do so, you will need to change the event processing rate within your XML properties file. To adjust the event processing rate, 1 Stop the currently running SmartConnector from operating. 2 From a Windows command line, access your XML properties file using the command cd %ARCSIGHT_HOME%/current/user/agent 3 Use WordPad or any XML Editor to open the .xml file for your HP OM destination, similar to the example below: 0Ajv5S8BABCAAeabNXP5Rw==.xml 4 From within the .xml file, search for the following: ProcessingSettings.ThrottleRate="50" This value controls the current processing event rate, and has a default value of 50 eps. 5 Change this value to the desired rate of events per second. For example, to lower the rate of events to 10 eps, change the value after the string to 10: ProcessingSettings.ThrottleRate="10" 6 Save the .xml file and exit the XML editor. 7 Restart the SmartConnector. If there are multiple destinations, repeat the steps above to change the rate for each destination, as required.
  • 14. Configuration Guide for Logger Forwarding Connector for OM 14 ArcSight Confidential