Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
ArcSight Education
For more information about Arcsight Education, visit www.arcsight.com or email traininginfo@arcsight.com.
Content customization,
ESM SOC environment Complete event database with rich sample data Interactive, hands-on training on the common ESM functionality and procedures Modular format enables users to select the topics and lessons applicable to their jobs Virtual environment allows return to lessons at any time to refresh learning
Condition Editor Dashboards and Datamonitors Report Generation and Report Authoring Cases Management Charts Usage and Authoring ArcSight Web Usage Rules Theory, Authoring and Operation Active Lists Definition Assets Definition and Management Vulnerability Definition Session Correlation
case solutions in the target security environment Utilizing ArcSight ESM Packaging facilities to assemble and distribute use case content This is an advanced workshop with prerequisites.
Case requirements Identification of qualifying business objectives Incorporating industry or organizational compliance requirements Leveraging ArcSight ESM native resource content and best practices
Settings, Navigator Panel and Resource Tree, Viewer Panel and Inspector Panel
Oracle 10g database infrastructure. A key area of focus will detail integration strategies for ArcSight Logger, Threat Remediation Manager and the Connector Appliance within ArcSight ESM environments.
Duration: 4 days
Controls and Notifications Administration of Connectors Overview of Multi-Manager Architectures Configuration of SNMP capabilities Installers for Manager, Database and SmartConnectors Basic DBA Skills Basic FlexConnector overview Basic third-party system interfaces overview
Logger, Connector Appliance, and Threat Remediation Manager ArcSight ESM multi-manager architectures for high-performance, high-availability and fail over Authentication credentials for ArcSight ESM environments Assessing and fine tuning ArcSight ESM Manager, Oracle Database Capacities and Event Throughput Using Oracle database tools to determine and optimize Oracles explain plan for ArcSight queries Assess and apply ArcSight best practices for database backup and recovery Customizing ArcSight Case Management and the ArcSight Web Interface Advanced ArcSight Network and Asset modeling
FlexConnector types Connector installation, schema groupings, and configuration file conventions Parsing methods fixed delimited, regular expressions, database and SNMP Event field and severity mapping FlexConnector Wizard Advanced configuration options such as multi-line REGEX, parser linking and conditional mapping
Attendees are expected to have a working knowledge of regular expressions to attend this course.
User Management Storage Appliance Field-based and RegEx Search Queries Filters, Saved Searches, Report Customization and Authoring Connector Operations and Management
Search Queries Using Filters and Saved Searches Logger Reporting Functions Specifying Report Data Customizing Report Displays Using and Customizing Dashboards Logger Alerts and Notifications Configuration Attribute Import, Export, Backup and Restore Connector Configuration Management
About ArcSight:
ArcSight (NASDAQ: ARST) is a leading global provider of compliance and security management solutions that protect enterprises and government agencies. ArcSight helps customers comply with corporate and regulatory policy, safeguard their assets and processes, and control risk. The ArcSight platform collects and correlates user activity and event data across the enterprise so that businesses can rapidly identify, prioritize, and respond to compliance violations, policy breaches, cybersecurity attacks, and insider threats. For more information, visit www. arcsight.com.
Modeling
Event Acquisition and Processing
Lifecycle
ArcSight Express User Interfaces Pre-configured Content Overview Manager Active Channels, Field
Sets, Filters, Dashboards, Reports, Workflow Cases, Notifications and Alerts Installing and Navigating the ArcSight Admin Console Network Modeling Wizard User and Group Administration Rules and Lists Use and Modification Notification Administration Storage Appliance User Interface
Facilities Logger Initialization and Setup Deployment Planning Navigating Logger Functionality Logger Configuration Settings Configuring Event Input and Output Managing User and Group Access
ArcSight, Inc.
5 Results Way, Cupertino, CA 95014, USA www.arcsight.com info@arcsight.com Corporate Headquarters: 1-888-415-ARST EMEA Headquarters: +44 870 351 6510 Asia Pac Headquarters: 852 2166 8302
2009 ArcSight, Inc. All rights reserved. ArcSight and the ArcSight logo are trademarks of ArcSight, Inc. All other product and company names may be trademarks or registered trademarks of their respective owners. ARST-SB002-041609-01