Lab 3 Network and Asset Model PDF
Lab 3 Network and Asset Model PDF
Table of Content
SECTION 1 - LAB OBJECTIVES ................................................................................................................................3
SECTION 2 - PREPARATION.....................................................................................................................................4
SECTION 3 - NETWORK MODELLING ...................................................................................................................8
SECTION 4 - ASSET MODELING ...........................................................................................................................14
SECTION 5 – APPLY YOUR NETWORK TO THE CONNECTOR ..................................................................16
SECTION 6 – REVIEW RESULTS ...........................................................................................................................20
Legend
Notation or important step or note. For example, the objective for each section.
Section 2 - Preparation
Section Objectives
In this section you will observe how events appear when they are not
modelled.
Navigate to the Active Channels resource tab (Ctrl + Alt + A) and right click on
<your name>’s Active Channels. Create a new active channel.
In the panel, configure it as below:
Click on OK
You should now see the Active Channel build
Right click on the Target Address column and select Columns -> Add/Remove Column
-> Target -> Target Zone Name
Observe
You should see that some of the fields are either not filled in, or are the
default entries (e.g. RFC1918). This demonstrates that the zone is not
being properly populated.
Section Objectives
Gain experience with how to work with ArcSight’s Network Model.
3.1 - Preparation
Log into ArcSight
Click on “Ctrl + Alt + S” to open the Asset tab
Review the default structure
Once the group has been created, right click on the group and select New Network. Enter
the name for your network and under the location select Deloitte Tokyo
Click on Add and add the zones you created in this section:
Section Objectives
Gain experience with how to work with ArcSight’s Asset Model.
Address OS Comments
Location: Toronto
System Asset (Category) Criticality:
High
Navigate to the Connectors resource (Ctrl + Alt + E) and expand the Replay Connectors
group:
Right click on the Instructor’s Replay and click on Configure. You will get a panel that
looks like the following:
Click on Add and add the network you just created. Use the top and down arrow, to ensure
that the network is higher than the Local network (or Local may fire before yours):
Note: It may take two to three minutes for the events to be re-zoned after this change.
Open the Active Channel that was created in Section 2. Check the zone and geo coding
and see if the events are now being tagged correctly. You should see the corrected Zone
Name and the Japanese flag appear under the Geo Flag URL.