0% found this document useful (0 votes)
58 views4 pages

Datasheet ArcSight Connectors

The document discusses HP ArcSight Connectors which provide scalable log collection from over 300 commercial products across physical, network, security and application layers. The connectors perform functions like parsing, mapping, filtering and classification of log events while also offering bandwidth controls and remote management capabilities. They integrate with the broader HP ArcSight platform for log management, security and compliance.

Uploaded by

Zoumana Diomande
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
58 views4 pages

Datasheet ArcSight Connectors

The document discusses HP ArcSight Connectors which provide scalable log collection from over 300 commercial products across physical, network, security and application layers. The connectors perform functions like parsing, mapping, filtering and classification of log events while also offering bandwidth controls and remote management capabilities. They integrate with the broader HP ArcSight platform for log management, security and compliance.

Uploaded by

Zoumana Diomande
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 4

Data sheet

Get scalable log collection today


HP ArcSight Connectors

Organizations archive and analyze log data for a broad set of


reasons ranging from security monitoring to IT operations, and from
Distributed processing
regulatory compliance to fraud detection. An effective log collection Once collected, log data needs to be analyzed in real time and
layer simplifies and optimizes the aggregation of logs across historically to address diverse use cases, such as security
thousands of devices and hundreds of locations. It serves as the monitoring and regulatory compliance. Typically, all processing is
foundation of log management and security information and event left to centralized log management and SIEM components.
management (SIEM) platforms.
However, HP ArcSight Connectors are architected to efficiently
Comprehensive and efficient enterprise-wide log collection goes offload the HP ArcSight log management and SIEM platforms from
beyond providing a common taxonomy to facilitate analysis. With centrally processing tasks, which are just as efficiently executed at
the rapid growth of the regulatory landscape, organizations need to the point of collection. To this end, HP ArcSight Connectors can also
collect from a much broader set of event sources, including physical, perform a variety of functions, including:
network, and security devices, hosts, databases, and a gamut of • Collection of raw logs in conjunction with parsing of individual
commercial and homegrown applications. Breadth and depth of device log events, and mapping both their values and schema into a
support in terms of log collection is therefore paramount. universal event taxonomy. This plays a significant role in enabling
cross-device searches, reporting, and correlation.
The various devices, hosts, and applications that generate logs span
hundreds or even thousands of physical locations. Log collection • Categorization or additional classification of events using a
infrastructures must therefore scale to meet the needs of large, common, human-readable format, which saves the end user
distributed heterogeneous networks. They must also deliver secure from having to be an expert in reading the output from myriad
and reliable audit-quality log collection with traffic management of devices from multiple vendors. Categorization also future
controls, simple deployment, and administration. proofs companies by making all content device independent—so
if you need to replace vendors, all reports and rules continue to
HP ArcSight Connector technology addresses these core challenges work seamlessly.
through a powerful log aggregation and optimization interface layer • Optional filtering of data that is extraneous to analysis and is not
that also represents the foundation for its broader log management required for retention by regulatory requirements or corporate
and SIEM platform. policies, such as system health alerts.

Breadth and depth of device support Highlights


The HP ArcSight library of out-of-the-box connectors provides
source-optimized collection for more than 300 commercial products. • Provides complete visibility with collection
These products span the entire stack of event-generating source support for any event source from the physical
types, from network and security devices to databases and enterprise
applications. In addition to the many sources commonly supported,
layer through the application layer
HP ArcSight Connector technology also uniquely supports:
• Offers ease of analysis through a common event
• Identity and access management
format for all log sources
• Data leak prevention
• Database activity monitoring • Creates universal content relevance with
• Mainframe pre‑built, vendor‑independent content
• Applications

Furthermore, the HP FlexConnector framework provides a


wizard-driven interface to build collection logic and to contextualize
logs from legacy and homegrown sources. Each is critical to
satisfying use cases such as compliance, fraud, and insider threats.
Audit-quality log collection Centralized management of log collection
Secure and reliable collection of audit logs is essential to ensuring infrastructure
the viability of log data for legal and forensics purposes. However,
There is significant overhead associated with ongoing updates,
many sources in remote locations are only capable of generating
upgrades, configuration changes, and general maintenance of a
logs over unreliable and unsecured protocols, such as syslog over
distributed log collection deployment. Even global organizations
user datagram protocol (UDP). HP ArcSight Connectors offer an
with numerous offices prefer to avoid expending valuable IT human
easily deployable and manageable localized collection option for
resources on managing yet another distributed infrastructure.
remote offices, which ensures end-to-end security and availability
Therefore, it is not enough for a log collection solution to simply
of log data.
support distributed deployment. HP ArcSight Connectors minimize
HP ArcSight Connectors offer local caching, so in the event of a ongoing administrative overhead through support for diagnostics,
connectivity loss between remote offices and central log aggregation universal and/or selective definition, alteration and roll out of log
points, there is no loss of critical event data. HP ArcSight Connectors collection parameters, and configuration settings from a centralized
also support automated failover to a secondary HP ArcSight Logger Web-based interface. The centralized management capabilities
or HP ArcSight Enterprise Security Manager (ESM) in the event that includes all software-based and appliance-based connectors
the primary destination is unavailable. throughout the environment.

Log traffic management Content sharing with HP ArcExchange


Remote offices such as retail stores often lack high bandwidth wide The HP ArcSight Connectors makes information sharing possible
area network (WAN) links to data centers. Additionally, any available with a simple click of a mouse. With the HP ArcExchange feature,
bandwidth needs to be prioritized for business-critical transactional users can download and upload custom-built connectors directly
traffic. To address these challenges, HP ArcSight Connectors offer to Protect 724, the HP Enterprise Security online user community.
granular bandwidth controls, compression of logs in transit, as well Connectors developed and shared by this community allow the
as prioritization and batching of log data by time and severity. collection of event data from customized and advanced applications,
databases, devices, etc. This capability, along with out-of-the-box
support for more than 300 products, makes the HP ArcSight platform
the broadest available SIEM solution on the market.
Adherence to hardware and software
deployment policies
Distributed, localized deployment of log collection infrastructure HP ArcSight platform integration
is critical for secure and reliable log collection. Yet organizations Regulatory retention requirements, audit reporting needs, IT
struggle with the headaches of deploying additional infrastructure operations troubleshooting, service level agreement, and proactive
at remote locations. Rack space is often limited and existing servers monitoring of security threats all represent a continuum in the
cannot be overloaded with additional agents for log collection. value chain of extracting context and intelligence from log data.
Furthermore, IT staff is often limited and cannot deploy and As such, it is logical to leverage a common collection infrastructure
manage log collection infrastructure at remote offices. To address across the full range of log collection and archival needs for an
these constraints, HP ArcSight Connectors are available in a range enterprise—and that is exactly what HP ArcSight Connectors offer.
of plug-and-play appliances and as software that can be easily As the data collection layer in the platform, connectors provide a
deployed and remotely managed. HP ArcSight Connectors provide comprehensive, robust, scalable, and easily manageable collection
a localized, yet agent-less collection option, which reduces the net infrastructure that can be used across its log management and
cost of acquisition and eliminates delay due to hardware selection, SIEM modules, as seen in figure 1. This is a distinct advantage of the
procurements and testing. integrated HP ArcSight platform, and it avoids the deployment of
multiple collection infrastructures that would be needed if different
For locations where no additional rack space is available but where vendor solutions were used for log management and SIEM. This
spare computing cycles are available on existing servers, HP ArcSight benefit applies to both appliance and software-based HP ArcSight
Connectors offer the flexibility of software-based deployments while Connector technology deployments.
still delivering strong centralized management capabilities.

2
Figure 1. Secure and reliable log collection across all devices and locations

HP ArcSight ESM
Central site

HP ArcSight C5400 HP ArcSight Logger

HP ArcSight Software
Remote site

Connectors

HP ArcSight C3400

HP ArcSight Connector appliance specifications


Model C3400 C5400 Software ConApp

Available as software Yes Yes Software only


Management Web browser, CLI Web browser, CLI Web browser, CLI
Red Hat Enterprise Linux v6.1, Red Hat Enterprise Linux v6.1, Red Hat Enterprise Linux, CentOS
OS
64-bit 64-bit and Oracle Enterprise Linux
Max EPS* 2,500 5,000 Depends on the hardware
CPU 1 x Intel® E5620, quad core, 2.4 GHz 2 x Intel E5620, quad core, 2.4 GHz
RAM 8 GB 16 GB
Storage 500 GB (RAID 0) 2 x 500 GB (RAID 1)
Chassis 1U 1U Customer supplied
1 x 460 W common slot platinum 2 x 460 W common slot platinum
Power
power supply power supply
Ethernet interfaces 4 x 10/100/1000 4 x 10/100/1000
Dimensions (DxWxH) 1.70" x 16.78" x 27.25" 1.70" x 16.78" x 27.25"

* Actual performance will depend on factors specific to a user’s environment.

3
Conclusion HP Software Services
HP ArcSight Connectors deliver flexible, scalable, audit-quality HP ESP Global Services take a holistic approach to building and
logs in a secure, reliable manner for security and compliance operating cyber security and response solutions and capabilities
monitoring. Centralized management of all connectors throughout that support the cyber threat management and regulatory
the environment increases operational efficiencies by making compliance needs of the world’s largest enterprises. We use a
deployment and administration simple. HP adapts to customer combination of operational expertise—yours and ours—and proven
needs by providing connectors in both software and hardware methodologies to deliver fast, effective results and demonstrate
appliance form factors, thereby, adapting to your requirements and ROI. Our proven, use-case driven solutions combine market-leading
not forcing you to adapt to ours. technology together with sustainable business and technical
process executed by trained and organized people.
Learn more about HP ESP Global Services at hpenterprisesecurity.com.
About HP Enterprise Security
HP is a leading provider of security and compliance solutions for
the modern enterprise that wants to mitigate risk in their hybrid For more information
environment and defend against advanced threats. Based on To know how you can get audit-quality log collection from all
market-leading products from HP ArcSight, HP Fortify, and HP event-generating sources across the enterprise, visit HP ArcSight
TippingPoint, the HP Security Intelligence Platform uniquely Connectors.
delivers the advanced correlation, application protection, and
network defenses to protect today’s hybrid IT infrastructure from
sophisticated cyber threats.

Get connected
hp.com/go/getconnected
Current HP driver, support, and security alerts
delivered directly to your desktop

© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and
services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial
errors or omissions contained herein.

Intel is a trademark of Intel Corporation in the U.S. and other countries. Oracle is a registered trademark of Oracle and/or its affiliates.

4AA4-1233ENW, Created May 2012; Updated October 2012, Rev. 1

You might also like