Endpoint Protection Small Business Edition

 View Only
  • 1.  ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 02:24 AM

    Hi,

    We're trying to integrate ArcSight SIEM to SEPM with embedded database. I cant find any documentation about this process. I also looked at other forum posts, it seems like no one really have the documentation for this. My best bet is to use external logging, but even the external logging dont have documentation on how to use it with ArcSight SIEM. nowAnyone tried doing this?

    Thanks,



  • 2.  RE: ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 02:32 AM

    Does below articles not help ?

    Exporting data to a Syslog server

    Article:HOWTO81169 | Created: 2012-10-24 | Updated: 2014-09-21 | Article URL http://www.symantec.com/docs/HOWTO81169


  • 3.  RE: ArcSight SIEM Integration to SEPM?

    Broadcom Employee
    Posted Mar 16, 2015 02:52 AM

    contact the Arcsight team as they will have documentation for the integration.

    http://www8.hp.com/h20195/v2/GetPDF.aspx/4AA5-3404ENN.pdf



  • 4.  RE: ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 06:08 AM
    Haven't seen any documentation from the Symantec side specifically for this. You would need to setup SEPM to send it's logs to arcsight. Symantec has documentation on configuring it from the SEPM side obviously but you're best off contacting arcsight to get the documentation on how to setup that piece of it.


  • 5.  RE: ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 06:41 AM

    Its not useful actually, I mean, try to read it. All it say are the common thing that you'll obviously do. Like, click this click that click OK. It didnt even tell what log facility to use on what external logging.



  • 6.  RE: ArcSight SIEM Integration to SEPM?
    Best Answer

    Posted Mar 16, 2015 06:44 AM

    Hey guys somehow we got it. I end up searching on google instead of symantec, very unexpected. Considering that we've been using symantec for more than 3 years.

    Thanks guys,



  • 7.  RE: ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 06:48 AM

    Ok so what's the answer?



  • 8.  RE: ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 06:55 AM

    Id just added the IP and port that 's it. The actual changes happend on another team handling SIEM ArchSight. They said they setup a ArchSight Reciever  or something like that, then they gave me IP address and ports. I think Symantec should do a testing of this thing and post a proper knowledge base considering that HP is a major player in enterprise I'm sure it is going to be useful to alot of users.



  • 9.  RE: ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 07:14 AM
    Symantec provides instruction on exporting syslogs. For anything further you'd need to look at arcsight documentation for specifics. You could always post an article on how to generically setup, this would be helpful. Thanks.


  • 10.  RE: ArcSight SIEM Integration to SEPM?

    Posted Mar 16, 2015 11:22 PM

    Symantec's post, this one below:

    Article:HOWTO81169 | Created: 2012-10-24 | Updated: 2014-09-21 | Article URL http://www.symantec.com/docs/HOWTO81169


    is already a generic instruction I think. As much as I want to post an instruction on SIEM ArchSight integration, unfortunately I'm not handling our ArchSight so that's not going to work for me and those guys handling it are sure busy as they're always around the clock doing monitoring and advisory stuff.