Endpoint Protection

 View Only
  • 1.  Connecting SEPM DB to ARC Sight for Logging

    Posted May 14, 2012 02:36 PM

    We use ARC Sight and have SEPM 11.0 with a SQL DB. My ARC Sight Tech is trying to have Logging flow

    from the SEPM DB to Arcsight Express application.

     

    Anyone out there have any ideas, there instructions are vague. This is apparently an ODBC connection.

     

    We are stuck. Any help would be much appreciated.

     

    Thanks,

     



  • 2.  RE: Connecting SEPM DB to ARC Sight for Logging
    Best Answer

    Posted May 14, 2012 03:35 PM

    You can configure the SEPM to send logs to Arc Sight.

    Admin tab >> select Local Site >> Configure External Logging

    Edit the General tab with all the appropriate information

    Edit the Log Filter tab with all the appropriate information

    Click OK



  • 3.  RE: Connecting SEPM DB to ARC Sight for Logging

    Posted May 14, 2012 05:01 PM

    That did it. We had seen it earlier, but it seemed way to simple.

     

    Thanks,