Professional Documents
Culture Documents
D2 - T8 - Reviewing Individual ESM Components - 092015
D2 - T8 - Reviewing Individual ESM Components - 092015
© Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
ESM Main Components
ArcSight Command Center https://<esmserver>:8443 ESM Console Linux, Windows, Mac
PROPERTIES……………………………<ARCSIGHT_HOME>/config/server.properties
CONFIGURATION & LOG FILES LOGS………………………………………<ARCSIGHT_HOME>/logs/default/
2 HA Option – IP Cluster
© Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
iDPU
ESM Resources
Active Actors
Users Cases
Channels Asset Connectors
s
Stages
Customers
Search
Filters
Dashboards
Saved
Searches Files
ESM Manager
Rules
Filters
Reports Integration
Commands
Knowledge
Query Pattern Base
Viewers Discovery
Lists
Notifications
3 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ESM 6.8c Overview
ESM High Availability (HA)
Active Channel in Web UI (ACC)
Query Speed Improvements with Bloom Filters*
ESM Web Service APIs Support
CFC Connector Capabilities
Correlation Enhancements
Larger Storage Capacity (12 TB)
Transition to Java 7
Support for RHEL and CentOS 6.5
Software Upgrades from ESM 6.0c Patch3 and ESM 6.5c SP1
4 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ArcSight Default Content Reputation
IdentityView Threat FISMA v5.0 IT Governance Sarbanes-
Resource * ESM v6.5c Express v4.0 Security HIPAA v2.0 JSOX v4.0 NERC v1.0 PCI v4.0
v2.5 Detector v2.0 SP1 v4.0 SP2 Oxley v4.0
Monitor v1.5
Active Channel 97 102 5 35 0 51 44 45 50 42 1 50
Active List 46 48 22 24 0 30 18 26 20 18 39 20
Asset 0 0 0 32 0 0 0 0 0 0 0 0
Dashboard 130 131 14 39 1 85 50 72 64 54 22 64
Data Monitor 322 313 24 96 1 252 130 228 200 160 2 200
Field Set 63 65 7 23 0 14 11 13 15 12 0 15
File 3 5 0 0 0 4 6 4 10 6 0 10
Filter 514 523 69 222 4 255 126 220 167 138 134 168
Integration Command 32 33 5 8 0 0 0 0 0 0 0 0
Integration Configuration 14 15 2 3 0 0 0 0 0 0 0 0
Integration Target 3 3 1 3 0 0 0 0 0 0 0 0
Profile 2 2 4 24 5 0 0 0 0 0 0 0
Query 792 772 131 266 2 492 194 359 210 198 86 212
Query Viewer 172 158 59 74 1 99 0 60 0 0 51 0
Report 558 551 22 162 0 312 195 259 204 197 37 204
Focused Report 88 91 0 0 0 10 7 9 7 7 0 7
Rule 150 179 29 65 0 81 65 75 73 65 73 74
Session List 16 27 0 2 0 2 0 1 1 0 0 1
Trend 70 68 10 8 1 26 0 15 36 0 10 39
Use Case 32 54 9 7 1 73 0 66 0 0 10 0
TOTAL 3 104 3 140 413 1 093 16 1 786 846 1 452 1 057 897 465 1 064
* Not all Resources included in these counts.
IT Governance Sarbanes-
Logger v5.5 PCI v3.01
v4.01 Oxley v4.0
Alerts 0 26 62 0
Reports 147 316 92 129
Filters 96 0 0 0
Total5 © Copyright 2015 Hewlett-Packard
243 Development
342 Company, L.P.
154The information129
contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ArcSight Event Schema
Event Schema – 400+ columns
• Event data collected, normalized, enhanced for monitoring and mining
ARC_LOGGER
plugin engine for MySQL
(1) Event storage is arranged by columns rather than rows. This means that the contents of all the name fields are stored together, the same with messages, end
times, etc. All Fields are indexed.
(2) PostgreSQL is an object-relational database management system (ORDBMS). (3) InnoDB is a storage engine for MySQL
8 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
CORR-engine event storage Events flow into the active retention period, and once a day,
CORR-e (e.g. at midnight) events are copied into the archives
DAY
TODAY Events Feed
TODAY
>>>> archiving DAY-7 data @ 00:00 on DAY-8h >>>>>
Yesterday All events time DAY-7
stamped(1) for a DAY-7 >>>> archiving DAY-6 data @ 00:00 on DAY-7 >>>>>
2 days back
particular day DAY-6
DAY-6
e.g. (12:00:00 a.m. to >>>> archiving DAY-5 data @ 00:00 on DAY-6 >>>>>
3 days back
DAY-5 DAY-5 Active
retention 11:59:59 p.m.) are
TIME LINE
April 26
Events Storage and Archiving
CORR-Engine operates on events available in the active retention period (Active “jobs”), and any
offline archives that have been activated.
When a days’ worth of events reaches the end of the retention period, they drop off of the
retention period’s memory, although their corresponding archive copy is retained indefinitely in
the archives.
As events flow into ESM, they receive a time stamp at Manager Receipt Time (MRT).
Retention period is the policy one set for how long to retain events in active memory for
correlation, for example, 30, 60, or 90 days.
CORR-Engine content (filters, rules, queries, query viewers, active channels, and data monitors)
evaluates the event data stored in this area (Active “jobs”).
10 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
HP ArcSight ESM Console
13 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ArcSight Command Center (ACC) – Administration
14 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger like GUI in ESM Console
15 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
HP ArcSight Java Console
ArcSight Java Console
!
Console version must be the same as ESM server
17 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Console menus
18 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Inspect / Edit
! Navigator Panel
Accessing resources CCE - Common Condition Editor
Events details & resources editor
Viewer
Dispay events, charts, reports,
dashboards, active channels
19 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Events Priority
Level
Color coded
(rated 0 to 10)
Lightning
Fired correlation rule
20 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Resource Navigation
User’ Content
Shared Content(1)
User’ Content
Shared Content(1)
21 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Drill down correlated
alert by accessing
base events
22 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Event’s
sequence
23 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Drill down correlated
alert by accessing
trigger rule
24 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Rule shows-up
in Inspect/Edit
panel
25 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Integrated
Workflow
Case
Editor
26 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Architecture
Architecture Sizing: Information Gathering
LOGS
SOURCES Security Cloud Application Network Physical Server CCTV
Database IDENTITY
29 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Protocols and Ports
30 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ArcSight ESM Process Management
• Single script to manage all ArcSight services
–Control process dependence and startup sequence
–Restart failed service
• Unified control of all ArcSight services with /etc/init.d/arcsight_services <command>(1)
–/etc/init.d/arcsight_services help
–/etc/init.d/arcsight_services [start | stop | status | …] [all | manager | mysqld | …]
(1) Starting with SUSE Linux support in ESM 6.5c SP1 the path changed for all users, regardless of operating system
31 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Command line application check
/etc/init.d/arcsight_services status | start | stop
All services are running Manager is not running
web service is available web service is mixed_statuses
manager service is available manager service is unavailable
execprocsvc service is available execprocsvc service is unavailable
logger_httpd service is available logger_httpd service is unavailable
logger_logger service is available logger_logger service is unavailable
logger_web service is available logger_web service is unavailable
mysqld service is available mysql service is available
postgresql service is available postgresql service is unavailable
32 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ESM Linux partition
• ESM software is installed in the /opt partition
separate partition
all ArcSight software & data under 1 single directory: /opt/arcsight
For RHEL, the XFS and EXT4 file system formats are supported.
For SUSE Linux, the EXT3 file system format is supported
• This directory is owned by user ‘arcsight’
• All arcsight operations should be run as ‘arcsight’, not ‘root’
• Event storage directory: /opt/arcsight/logger/data/logger
• Event archive directory: /opt/arcsight/logger/data/archives
1 directory per day (don’t forget archiving logs entries)
33 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
A Primer to HA
HA Architecture explained Intranet
ESM
SECONDARY (host name esm1)
Interface configuration
16.103.74.224 Secondary (eth0) “esm1” File System
192.168.145.224 (eth1)
16.103.74.23 cluster (service Ip/name) Interlink cable
Distributed Replicated Distributed Replicated
Block Device eth-1 eth-1 Block Device
192.168.145.24 192.168.145.224
35 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
HA and iPDU (optional) Intranet
iPDU
36 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
STONITH (shoot the other node in the head)
HA architecture
Enabling technology for failover
• Needed when primary is crippled and will not release resources
– Communication problems – primary cannot receive stop request
– Software problems (e.g. out of memory or other resources)
37 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Fail Over Illustrated 1/2 Intranet
Interlink cable
Secondary has:
Distributed Replicated Distributed Replicated
Operating System started Block Device Block Device
eth-1 eth-1
IP cluster pacemaker activated and 192.168.145.24 192.168.145.224
monitoring Primary
ESM application stopped
DRBD handling disk level block replication
Disk 1 Disk 2
38 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Fail Over Illustrated 2/2 Intranet
39 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Architecture: Key points
40 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Managing ESM
Managing and Configuring ESM
42 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Managing ESM license key
cd /opt/arcsight/manager/bin
./arcsight deploylicense
43 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ESM Backup Overview
From Administrator’s Guide and ArcSight Command Center User’s Guide
1. Configuration Parameters Backup
• Configbackup
backs up certain essential configuration information such as search settings and the configuration of archives
(not the archives themselves) in configs.tar.gz in opt/arcsight/logger/current/arcsight/logger/tmp/configs
2. Database dump / import
• export_system_tables
Exports database tables by generating 2 files: a temporary parameter file and the actual database dump file,
arcsight_dump_system_tables.sql, which is placed in /opt/arcsight/manager/tmp.
• import_system_tables
Imported file must be the one that export_system_tables utility created
3. Event Data Archiving
• From ArcSight Command Center GUI
Storage and Archive Tab is used to activate and Schedule Archive Jobs
44 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
ArcSight ESM 6.8c Documentation
ESM Product Guides Standard Content Guides
• ESM 101 – Concepts for ArcSight ESM 6.8c • Cisco Monitoring
• Administrator’s Guide – ArcSight ESM 6.8c • Configuration Monitoring
• User’s Guides for • Intrusion Monitoring
• ArcSight Console • IPv6
• ArcSight Web • NetFlow Monitoring
• ArcSight Command Center • Network Monitoring
• Installation and Configuration Guide • ArcSight Core Security, ArcSight
• Release Notes - ArcSight ESM 6.8c Administration, and ArcSight System
• Upgrade Guide - ArcSight ESM • WorkFlow
User Interface Help Facilities
• Searchable Online Product Guides
• Context-sensitive Help
45 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Thank You
Questions ?
© Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use