SIEM Integration - OpenText ArcSight

This article will detail how to set up your OpenText ArcSight with your Sharetru site.

Note: Do not toggle the Enable to "on" until you have filled out the form illustrated below and competed a test of the connection.

Use the SIEM "Select Service..." dropdown and select OpenText ArcSight.
image-20240715-222025

 

 The only format available for OpenText ArcSight is CEF.
image-20240715-225127(2)

 

To view an example of the SIEM test message click the link button
image-20240715-222607


After configuring your format you will need to select the Protocol, Hostname or IP address, and Port.
image-20240715-153626

You may choose from TLS, TCP or UDP.

We recommend TLS for security or TCP if TLS is not available for your SIEM instance.

If TLS is selected you will have the option to utilize a signed certificate. 
Alternatively, if you are using a self-signed certificate you should toggle this off.
image-20240715-200204

After the form is completed click "Save".

image-20240715-201420

Now, you will need to test the connection. Click the "Test Connection" button.
image-20240715-201448

If the connection is successful you will receive a message verifying that result.
siemtestsuccess

*You should verify that the message was received by your OpenText instance. *

However, if the connection is not successful you will receive a message regarding the failure. 

Upon completing the test you may toggle the "Enable" switch on and then click "Save".

This will finalize the SIEM integration set up.image-20240715-203324

image-20240715-230804