Professional Documents
Culture Documents
Paladion ArcSight Training3
Paladion ArcSight Training3
Paladion ArcSight Training3
The following are the various ways in which you can display Data
Monitors within your Dashboard
• Asset Category Count — enumerates the number of events that occur per
asset category (by priority within a time interval)
• Event Graph — draws a real time diagram of selected event activity
• Geographic Event Graph — draws a real time geographic map of selected
event activity
• Hierarchy Map — draws an image made up of proportionally sized panels
where each panel represents a group of events selected by group fields
selected in the source node identifier.
Event-Based Data Monitors (2 of 2)
Are also event based and evaluate the event stream, but have the
capability to perform special analytic functions that rules alone
cannot. Work analytically in conjunction with rules.
When creating a Data Monitor, use the Inspect/Edit panel and select the type
of Data Monitor you would like to configure.
• XLS,PDF,HTML,CSV or RTF
Reports
Name
The name of the field appears as a column heading in the report unless you
specify an alias
Alias
An alternate name that replace the original field name as the column heading
in the report
COL (Column)
Decides the alignment of fields in the report i.e. which column come first
Function
When you select a field to use as a "group by" factor in a report, also choose
a function by which to evaluate the grouping. These are the same functions
described above for SRT BY.
Scheduled and
Archived Reports
Archived reports are
retrieved for immediate
viewing, without required
to rerun the report. In
addition, we can
schedule a report for
automatic archiving, on a
yearly, monthly, weekly,
daily, or hourly basis
Data Sources
• Events
• Active/Session Lists
• Notifications
• Cases
• Assets
• Query
or
• Trend Query
Trends
What is a Trend?
• A trend is an ArcSight resource that defines how and over
what time period data will be evaluated for trends.
Trend Characteristics:
• A trend is always based on a query
• The trend results are stored in a trend table in the
ArcSight Database, and are themselves query-able
• Trends can also be used as the primary data source for a
report
Trend Characteristics
Trend Types:
Interval
• Time range from X to Y
• Example: Events - Top 10 events for each hour
Snapshot
• No time range
• Example: Assets - Top 10 assets by vulnerability count
Trends - Lifecycle
• Create Query
Define Basic type (e.g. event, asset,G)
Select columns, grouping, sorting
• Create Trend
Choose query, duration, G
Choose columns (subset)
Setup schedule
• Create Query
Choose the trend
Select columns, grouping, sorting
• Create Report
Choose the trend-based query
Specify report settings
Trend – Performance Considerations
What is Logger ?
• Logger Gauges
o Number of incoming events per second (EPS In)
o Number of outgoing events per second (EPS Out)
o Percentage of the CPU being used
• Monitor
o The Monitor tab displays the real-time and historical status of Receivers,
Forwarders, and Storage, CPU, and disk usage statistics.
• Analyze
o The Analyze tab contains the fields used to query Logger’s saved log
results.
Logger Control Panel
• Reporting
o The Reporting tab provides access to Logger reporting tools, including
functionality to run reports, view saved reports, and create new reports.
• Configuration
o The Configuration tab provides access to basic Logger functions for
setting up the Logger application environment, such as creating a
receiver or disabling an existing forwarder.
• System Admin
o The System Admin tab shows Logger’s system information, and
provides the interface to manage Logger users and network settings.
Setup of Logger
Users and Groups
• System Admin
• Logger Rights (Basic User Operations)
• Logger Search
• Logger Report
User Groups
Managing Users
Configuring Logger Input and Output
•Receivers
•Forwarders
•ESM Destinations
•Peer Loggers
•Device and Device Groups
Receivers
• Reporting
o The Reporting tab provides access to Logger reporting tools, including
functionality to run reports, view saved reports, and create new reports.
• Configuration
o The Configuration tab provides access to basic Logger functions for
setting up the Logger application environment, such as creating a
receiver or disabling an existing forwarder.
• System Admin
o The System Admin tab shows Logger’s system information, and
provides the interface to manage Logger users and network settings.