Skip to main content

Micro Focus Arcsight

Micro Focus ArcSight is a comprehensive Security Information and Event Management (SIEM) platform designed for enterprise security monitoring, threat detection, incident response, and compliance management. ArcSight collects, correlates, and analyzes security events and log data from across an organization's IT infrastructure to identify security threats, anomalies, and compliance violations in real-time.

CategorySIEM
DirectionQuery source
Sign-inNone
Query languagesSTIX

Before you start​

warning

The setup page can't take credentials for Micro Focus Arcsight yet. Create the connection, then contact Huntbase support to finish signing it in.

For the vendor's own instructions, see ArcSight Logger user management documentation.

Connect Micro Focus Arcsight​

  1. Go to Connections and click New connection, or click New connection on the Micro Focus Arcsight product page.
  2. On Product, pick Micro Focus Arcsight and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Micro Focus Arcsight lives:

FieldRequiredNotes
Server AddressYesThe hostname or IP address of your ArcSight Logger.
PortYesThe HTTPS port of the Logger web interface, usually 443. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Query it​

Once connected, Micro Focus Arcsight can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​