Micro Focus Arcsight
Micro Focus ArcSight is a comprehensive Security Information and Event Management (SIEM) platform designed for enterprise security monitoring, threat detection, incident response, and compliance management. ArcSight collects, correlates, and analyzes security events and log data from across an organization's IT infrastructure to identify security threats, anomalies, and compliance violations in real-time.
| Category | SIEM |
| Direction | Query source |
| Sign-in | None |
| Query languages | STIX |
Before you start
The setup page can't take credentials for Micro Focus Arcsight yet. Create the connection, then contact Huntbase support to finish signing it in.
For the vendor's own instructions, see ArcSight Logger user management documentation.
Connect Micro Focus Arcsight
- Go to Connections and click New connection, or click New connection on the Micro Focus Arcsight product page.
- On Product, pick Micro Focus Arcsight and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Micro Focus Arcsight lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname or IP address of your ArcSight Logger. |
| Port | Yes | The HTTPS port of the Logger web interface, usually 443. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Query it
Once connected, Micro Focus Arcsight can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog