Advertisement

09.30.2008 at 01:42PM PDT, ID: 23776134 | Points: 500
[x]
Attachment Details

ArcSight 3.5 ESM assistance requested

Asked by jtsapos in Intrusion Detection Systems (IDS), Oracle Database, Network Security

Tags: , , ,

We are going to be standing up several sites nationwide in the near future and I would like to find out what is the best way to add them in ArcSight so that we can monitor them at all times.
These will be "cold storage" sites with one terminal per site and will probably be physically removed off-line at the end of each business day.
We need to be able to monitor them at all times, i.e. we need to be able to see when they come back on-line, when was the last time they were on-line, etc.
I believe I would need to set up a zone in Arcsight or a group or something to include all the sites collectively and set up a general filter or rule(s) on the group for central administration. Any help on this would be greatly appreciated.
Thank youStart Free Trial
 
 
[+][-]10.06.2008 at 04:30PM PDT, ID: 22655412

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.06.2008 at 07:17PM PDT, ID: 22656182

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.08.2008 at 05:24AM PDT, ID: 22668206

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.08.2008 at 02:25PM PDT, ID: 22673646

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.15.2008 at 07:59AM PDT, ID: 22721842

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20081112-EE-VQP-43 / EE_QW_2_20070628