Last updated on August 9, 2019
ArcSight Logger is one of products from Micro Focus SIEM platform. It streams real-time data and categorizes them into specific logs and easily integrates with Security Operations. As a result, organizations of any size can use this high performance log data repository to aid in faster forensic analysis of IT operations, application development, and cyber security issues, and to simultaneously address multiple regulations.
Summary
Analyzer
Search
Live Event Viewer
Dashboard
Reports
Configuration
YouTube Video for Web Gui OverView:
Search Example:
a.
sourceAddress=1.1.1.2 and name startswith “TCP” and name contains “DEN” | fields requestUrl
b.
((name CONTAINS “Search.cgi Command Injection Vulnerability” ) and destinationAddress = “14.47.251.171”) AND deviceInboundInterface CONTAINS “11”| fields sourceAddress,destinationAddress,deviceInboundInterface
c.
CEF “failed” | dedup name
Removes duplicate events from search results. That is, events that contain the same value in the specified field. The first matching event is kept, and the subsequent events with the same value in the specified field are removed.
It will search all logs which has ‘failed’ word then listed first found one in name field.
References:
ArcSight Logger是MicroFocus SIEM平台产品之一,提供实时数据流与特定日志分类,易于与安全运营整合。适用于各种规模组织,助力快速IT操作法医分析、应用开发及网络安全问题,同时应对多项法规。其功能包括分析器搜索、实时事件查看、仪表板、报告与配置。







450

被折叠的 条评论
为什么被折叠?



