Arcsight Platform 24.2.1 Release Notes
Arcsight Platform 24.2.1 Release Notes
Legal Notices
Open Text Corporation
275 Frank Tompa Drive, Waterloo, Ontario, Canada, N2L 0A1
Copyright Notice
Copyright 2001 - 2024 Open Text.
The only warranties for products and services of Open Text and its affiliates and licensors (“Open Text”) are as may be
set forth in the express warranty statements accompanying such products and services. Nothing herein should be
construed as constituting an additional warranty. Open Text shall not be liable for technical or editorial errors or
omissions contained herein. The information contained herein is subject to change without notice.
Trademark Notices
“OpenText” and other Open Text trademarks and service marks are the property of Open Text or its affiliates. All other
trademarks or service marks are the property of their respective owners.
Contents
What's New 9
Database Upgrade 9
End of Support Announcements 9
ArcSight Dashboard and Widget SDK 9
Collectors and Connectors in Transformation Hub (CTH) 10
Technical Requirements 11
Downloading the Installation Files for 24.2.1 11
Downloading and Verifying the Installation Files 11
Installing the 24.2.1 Patch 12
Upgrading the Database to 24.2.1 as a Root User 13
Upgrading the Database to 24.2.1 as a Non-root User 14
Upgrading the Database to 24.2.1 on ArcSight Recon R8000 and R8100
Appliances 15
Known Issues 15
Known Issues Related to ArcMC 16
16
736019 — Selecting a value for ArcMC Container Memory Limit Returns an
unformatted screen error 16
698065 — On Azure, Intermittent Login Errors 17
648050 — Routing Rules Character Limitations 17
612094 — Fusion ArcMC Throws 503 Error After Restoring Configuration
Data (AWS, Azure and On-premises) 17
425040 — In Deployment/Topology View, Logger or ESM Destination for
TH Shows Unknown IP Address 18
408195 — Importing a Host File on Fusion ArcMC Points to a Different Log
Folder 18
408194 — Fusion ArcMC Session License Expiration 18
363022 — On G10 Appliance, Gateway Not Correctly Configured After
Restore 18
363017 — On G10 Appliance, IP Address Not Correctly Configured After
Restore 18
359190 — On G10 Appliance, ArcMC Does Not Validate IP Addresses for
NIC Ports 19
773027 — Restored Ability to Specify Time Ranges for Custom Reports and
Dashboards Because the Enter Parameters Modal is not Displayed 46
566085 — Network Chart Data are No Longer Presented in Portions and
Cut 46
Resolved Issues Related to Search 46
733209 — Scheduled Searches no Longer Display an Error When You Try to
Load a Field Summary on a Completed Run 46
616090 — For System Search Queries, #SSH Authentication No Longer
Generates an Error 47
608098 — Certain top/bottom Queries and Fields that Begin With "Device"
no Longer Fail 47
Resolved Issues Related to SOAR 47
591118 - Enrichment History - Sort By Capability And Status Functionality
Does not Sort By Alphabetical Order 48
655004 - SOAR FortiAnalyzer Plugin Should Accept Dynamic Ports 48
724037 - Enhancement - SOAR Should Support Updating User's Email
Address and Username When Changed in FUM 48
719017 - Proxy Option Missing in SMTP Mail Server Integration
Configuration 48
737015 - API Documentation soar-api/js-api-doc Search Does Not Work 49
8502032 - ''Access Denied'' Error During Action Rollback with Manage
SOAR Integrations Permission 49
853043 - SOAR Response Headers Returning Only One Header Key Value
Even When Multiple Keys Are Present 49
853078 - EWS Mail Receiver Should Get All Body Content 49
854004 - Case and Alerts Details Missing in Email Notification 49
857027 - Access is Denied when Creating a Search in SOAR cases including
Alert Source Rule Name Condition 49
866085 - CreateTicketComment Method Does Not Work Properly 49
877024 - Missing Job ID Scope Item in EnCase Plugin 49
880090 - SOAR Performance Issue Due to Lack of Index for Ticket Table 50
190609 - Missing Type Parameter in Scope Action Parameter 50
Resolved Issues Related to Transformation Hub 50
Contacting OpenText 51
Additional Documentation 51
Publication Status 52
Component Version
The documentation for this product is available on the ArcSight documentation website in
HTML and PDF formats. If you have suggestions for documentation improvements, click
comment or support on this topic at the bottom of any page in the HTML version of the
documentation posted on the ArcSight Platform CE Documentation page or the
documentation pages for the included products.
What's New
Database Upgrade
The 24.2.1 ArcSight Platform release contains a database upgrade from the 24.2 release. This
upgrade addresses previous issues that might impact ingestion performance. It is strongly
recommended that you install this update so that the ingestion performance is not impacted.
Technical Requirements
For more information about the software and hardware requirements required for a successful
deployment, see the Technical Requirements for ArcSight Platform. These Technical
Requirements include guidance for the size of your environment based on expected workload.
OpenText recommends the tested platforms listed in this document.
Customers running on platforms not provided in the Technical Requirements or with untested
configurations will be supported until the point OpenText determines the root cause is the
untested platform or configuration. According to the standard defect- handling policies,
OpenText will prioritize and fix issues we can reproduce on the tested platforms.
Refer to "Installing the 24.2.1 Patch" on the next page for instructions about how to install this
update.
Evolving security needs imply the renewal of certificates for the signature verification
procedure. To ensure a successful verification of your product signature, download the
latest public keys file before proceeding with the verification process (step 1 of the Get the
Public Keys procedure).
OpenText provides a digital public key that is used to verify that the software you
downloaded from the OpenText software entitlement site is indeed from OpenText and
has not been tampered with by a third party. For more information and instructions on
validating the downloaded software, visit the OpenText Code Signing site. If you discover a
file does not match its corresponding signature (.sig), attempt the download again in case
there was a file transfer error. If the problem persists, please contact OpenText Customer
Support.
cd /tmp/arcsight_db_patch
/tmp/arcsight_db_patch/db_upgrade -c upgrade-utilities
/opt/arcsight-db-tools/scripts/watchdog.sh disable
/opt/arcsight-db-tools/db_installer stop-db
/tmp/arcsight_db_patch/db_upgrade -c upgrade-db-rpm
/opt/arcsight-db-tools/kafka_scheduler start
/opt/arcsight-db-tools/scripts/watchdog.sh enable
For information about using the ArcSight Platform Installer, see Using ArcSight Platform
Installer to Deploy Off-cloud as a Root User in the Administrator's Guide for ArcSight Platform
24.2.
2. After the line "Cmnd_Alias ARCSIGHT = \", add sudoers settings listed below.
/opt/vertica/sbin/update_vertica, \
/usr/bin/id dbadmin, \
/bin/[ -e /opt/vertica/data/ ], \
/bin/[ -e /usr/bin/sudo ], \
/bin/[ -f /etc/redhat-release ], \
/bin/[ -e *dbadmin/ ], \
sudo su -
3. Perform steps 2 through 8, described in the “Upgrading the Database to 24.2.1 as a Root
User” section above.
Known Issues
These issues apply to common or several components in your ArcSight Platform deployment.
For more information about issues related to a specific product, please see that product's
release notes.
OpenText strives to ensure that our products provide quality solutions for your enterprise
software needs. If you need assistance with any issue, visit OpenText Support, and then select
the appropriate product category.
All issues listed in this section belong to the OCTCR33I repository, unless otherwise noted.
Upgrading the Database to 24.2.1 on ArcSight Recon R8000 and R8100 Page 15 of 52
ArcSight Platform CE Release Notes
The output of the command should show a value of 4/4 (the pod's READY state) and of
Running (the pod's STATUS) for the fusion-arcmc-web-app pod.
3. Go to the ITOM Management portal and click on the 3 dots menu. Select the Reconfigure
option.
4. Go to ArcMC Configuration and select a value for ArcMC Container Memory Limit (4GB,
5GB, 6GB, 7GB or 8GB).
5. Click the Save button.
cd /mnt/efs/<nfs_folder>/
$ kubectl delete pods -n $(kubectl get namespaces | grep arcsight | cut -d '
' -f1) $(kubectl get pods -n $(kubectl get namespaces | grep arcsight | cut
-d ' ' -f1) | grep arcmc | cut -d ' ' -f1)
359190 — On G10 Appliance, ArcMC Does Not Validate IP Addresses for Page 19 of 52
ArcSight Platform CE Release Notes
providing a space between the colon and the number of days, the SearchManager pods fail to
start and instead enter into a CrashLoopBackOff state.
Workaround: Ensure that you include a space when specifying the value of the Elasticsearch
Data Retention Period field. For example, a value of 0: 90 is valid, where 0 is the tenant ID, 90 is
the number of days to retain the Elasticsearch Indices, and there is a space between : (colon)
and 90. A value of 0:90 is invalid because there is no space between : (colon) and 90.
As a result, analytics is unable to load the other data sources, such as Resource, Share, VPN,
and Repository.
Workaround: Perform the following steps to specify each data source for the data source
configuration:
1. Open a certified web browser.
2. Specify the following URL to log in to the OMT Management Portal: https://<omt_
masternode_hostname_or_virtual_ip_hostname>:5443.
3. Select Deployment > Deployments.
4. Click ... (Browse) on the far right and choose Reconfigure. A new screen will be opened in a
separate tab.
5. Click Intelligence.
6. In the Analytics Configuration - Database section, modify Database Loader Data Sources
field's value to ad,pxy,res,sh,vpn,repo.
611096 — Analytics Fails to Load Data Sources Except for AD and Proxy Page 21 of 52
ArcSight Platform CE Release Notes
8. Click Update.
9. Restart the interset-api pods:
a. Launch a terminal session and log in to the master or worker node.
b. Execute the following command to retrieve the namespace:
400584 - Either the Intelligence Search API or Login to the Intelligence UI or Page 22 of 52
ArcSight Platform CE Release Notes
8. Click Update.
9. Restart the interset-api pods:
a. Launch a terminal session and log in to the master or worker node.
b. Execute the following command to retrieve the namespace:
399297 - Intelligence Search API Fails with a Timeout Error (esSocketTimeout Page 23 of 52
ArcSight Platform CE Release Notes
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
scale statefulset interset-logstash --replicas=0
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
edit configmaps logstash-config-pipeline
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
scale statefulset interset-logstash --replicas=<number_of_replicas>
401549 - Most Pods Enter into the CrashLoopBackOff State if the KeyStore Page 24 of 52
ArcSight Platform CE Release Notes
613050 - Installer Does Not Validate the Value You Specify for
Elasticsearch Data Retention Period
Issue: In the OMT Management Portal > Configure/Deploy page > Intelligence > Elasticsearch
Configuration section, the installer does not validate the value you specify for the Elasticsearch
Data Retention Period field. The tool-tip for the Elasticsearch Data Retention Period field
suggests that you should specify a value greater than 30 for indices retention. However, there
is no validation preventing you from entering a value that is less than 30. If you specify a value
that is less than 30, the value for Elasticsearch Data Retention Period will be set to the
minimum default value of 30 days.
Workaround: There is no workaround at this time.
613050 - Installer Does Not Validate the Value You Specify for Elasticsearch Page 26 of 52
ArcSight Platform CE Release Notes
Workaround: You must restart the Elasticsearch cluster to refresh the Elasticsearch
environment.
Workaround: If this issue occurs, you should set up an SSH connection between the Logger and
the database. This workaround applies to an off-cloud deployment of the ArcSight Database on
a server running RHEL 9.2 as well as on an appliance for ArcSight Recon.
898339 — AWS Fresh Installation Fails on EKS Later Than 1.28.3 Page 28 of 52
ArcSight Platform CE Release Notes
Workaround:
1. Attempt to re-run the upgrade.
2. If re-running the upgrade does not solve the problem, run the following command on
every node where the error occurs:
<OMT_HOME>/bin/kube-restart.sh
For example:
/opt/arcsight/kubernetes/bin/kube-restart.sh
If you run the manual upgrade and the version of firewall is equal or greater than 0.9.0
(firewall-cmd --version) you might prevent upgrade failures by running the following
commands on every node:
firewall-cmd --add-forward
firewall-cmd --add-forward --permanent
firewall-cmd --add-interface cni0
firewall-cmd --add-interface cni0 --permanent
These steps are included into the arcsight-install --cmd upgrade command, so they're not
necessary with arcsight-install upgrades.
844085 — An Operation to Add a New Role or Group to a User Succeeds, But Page 30 of 52
ArcSight Platform CE Release Notes
.. <> ...
3. List the relations to see the flag, remove it and exit the psql with "\q" and ssh pod with
"exit"
4. Restart the autopass pod using kubectl delete pod, and then make sure the container
starts correctly with 2/2 Ready status.
l "186007 — An Exported Report Might Have Format Issues" on the next page
l "162054 — Warning Message is Displayed: Query Plan Prevents Materialized View (MV)
Sharing" on the next page
Workaround: Refresh the page to load the Contract & Usage page.
l "793025 — Scheduled Searches: Unable to Navigate Through Page Elements Using the Tab
Key" on the next page
l "774031 — Under Certain Rare Conditions, the fusion-db-search-engine Pod Can Run into
High Memory and CPU Utilization, Causing System Instability" on the next page
l "757008 — Saving Real-time Searches as Fixed-time Searches: Incorrect Results Count
Display on the Manage Search Tab after Auto-pausing by Selecting a Histogram Bar" on
page 37
l "766026 — User Preferences Drop-down Menus are Closed if You Click in the Scrollbar" on
the next page
l "674039 — System Erroneously Clears All Search Data Instead of Refreshing the Search
Results" on page 37
l "609036 — Upgrade Issues: Searches That Use the "All Fields" Fieldset and the "All Time"
Time Range Do Not Complete" on page 37
l "608115 — Vulnerabilities: System Query is Duplicated With Two Different Names" on
page 37
l "610161 — Incorrect search result when filtering with "id" field" on page 38
l "179782 — Scheduled Search Appends Erroneous Values to the Run Interval" on page 38
l "113040 — CSV File Export Fails after You Change the Date and Time Format" on page 38
898088 — Search Tab Has a Black Background and User Cannot Create a New Page 35 of 52
ArcSight Platform CE Release Notes
113040 — CSV File Export Fails after You Change the Date and
Time Format
Issue: After modifying the date and time format in preferences, the CSV export function for
saved searches runs before the preference change fails.
Workaround: Run the scheduled search again, then save it. Select the CSV icon to download
the file
610161 — Incorrect search result when filtering with "id" field Page 38 of 52
ArcSight Platform CE Release Notes
l 895045 — SOAR Permissions and Respond in Left Navigation is shown even after deploying
SOAR.
l 900041 — SOAR Swagger UI is not accessible for MSSP users.
598065 — SOAR Productivity Widget does not show Velocity Graph Page 39 of 52
ArcSight Platform CE Release Notes
routed to the destination topic. The result is that the destination topic could contain
unintended CEF events.
If the output shows all instances are running on the same worker node, Schema Registry must
be restarted to spread the instances across worker nodes.
2. Restart Schema Registry.
Verify restart has completed by waiting until all Schema Registry pods have a status of Running,
and a small age value of the minutes or seconds since you performed the restart.
After the restart completes, verify the instances are now running on different worker nodes.
In a multi-node scenario, a topic used internally by Schema Registry may get configured with
too few replicas, which reduces reliability and can make the registry fail during failover. Check
the topic's configuration to verify it has the proper replica count (replication factor).
3. In a multi-node deployment, identify the replica count for the topic "_schemas". Set the
topic to be used in later commands.
409228 — Schema Registry Instances May Be Allocated to Single Worker Node Page 41 of 52
ArcSight Platform CE Release Notes
topic="_schemas"
5. If the replication factor is not 3, perform the following steps to change the
configuration: Get the list of brokers to set as replicas, including the topic's partition
leader. If the cluster has more than three brokers, limit the replicas to three.
topicfile=/tmp/topic.json
assignfile=/tmp/assign.json
printf '{"topics": [{"topic": "%s"}], "version":1}' $topic > $topicfile
kubectl cp $topicfile $namespace/th-kafka-0:$topicfile
kubectl -n $namespace exec th-kafka-0 -- kafka-reassign-partitions --broker-
list "$allbrokerids" --bootstrap-server th-kafka-svc:9092 --generate --
topics-to-move-json-file $topicfile > $assignfile
sed -i '1,/Proposed partition reassignment/d' $assignfile
sed -i -r "s/(,.replicas.:\[)([0-9,]+)/\1$blist/" $assignfile
sed -i 's/,\s*"log_dirs"\s*:\s*[[][^]]*[]]//' $assignfile
kubectl cp $assignfile $namespace/th-kafka-0:$assignfile
rm -f "$assignfile" "$topicfile"
8. Verify the reassignment completes by running a verify command with the same input file.
409228 — Schema Registry Instances May Be Allocated to Single Worker Node Page 42 of 52
ArcSight Platform CE Release Notes
9. Since the replicas have changed, run a preferred leader election for the topic's partition.
electfile=/tmp/election.json
printf '{"partitions": [{"topic": "%s","partition":0}]}\n' $topic >
$electfile
kubectl cp $electfile $namespace/th-kafka-0:$electfile
rm -f "$electfile"
kubectl exec -n $namespace th-kafka-0 -- kafka-leader-election --bootstrap-
server th-kafka-svc:9092 --election-type preferred --path-to-json-file
$electfile
Also in a multi-node scenario, an internal ArcSight topic may get configured with too few
replicas, which reduces reliability of Stream Processor metrics and can prevent ArcMC from
displaying the metrics. Check the topic's configuration to verify it has the proper replica count.
In a multi-node deployment, identify the replication factor for the topic "th-arcsight-avro-sp_
metrics".
10. Set the topic to be used in later commands.
topic=th-arcsight-avro-sp_metrics
Repeat all of steps 4 and 5 above to check the topic and modify it if needed. The topic needs to
have the same replica count as the previous topic: three.
Resolved Issues
These issues apply to common or several components in your ArcSight Platform deploy. For
more information about issues related to a specific product, please see that product's release
notes, as applicable.
All issues listed in this section belong to the OCTCR33I repository, unless otherwise noted.
As a result, analytics is unable to load the other data sources, such as Resources, Share, VPN,
and Repository.
Fix: This issue has been resolved now.
729040 — SearchManager Pods Fail Due to the Absence of Spacing in the Page 45 of 52
ArcSight Platform CE Release Notes
779004 — VPM Conditions/Triggers are now Being Applied for Scheduled Page 46 of 52
ArcSight Platform CE Release Notes
591118 - Enrichment History - Sort By Capability And Status Functionality Does Page 48 of 52
ArcSight Platform CE Release Notes
880090 - SOAR Performance Issue Due to Lack of Index for Ticket Table Page 50 of 52
ArcSight Platform CE Release Notes
Contacting OpenText
For specific product issues, contact OpenText Support.
Additional technical information or advice is available from several sources:
l Product documentation, Knowledge Base articles, and videos.
l The OpenText Community pages.
Additional Documentation
The ArcSight Platform documentation library includes the following resources:
l Administrator's Guide for ArcSight Platform, which contains installation, user, and
deployment guidance for the ArcSight software products and components that you deploy
in the containerized platform.
See the guide that corresponds to your deployment:
o Administrator's Guide for the ArcSight Platform 24.2 - AWS Deployment
o Administrator's Guide for the ArcSight Platform 24.2 - Azure Deployment
o Administrator's Guide for the ArcSight Platform 24.2 - Google Cloud Deployment
o Administrator's Guide for the ArcSight Platform 24.2- Off-Cloud Deployment
l Technical Requirements for ArcSight Platform, which provides information about the
hardware and software requirements and tuning guidelines for the ArcSight Platform and
the deployed capabilities.
l User’s Guide for ArcSight Platform, which is embedded in the product to provide both
context-sensitive Help and conceptual information.
l Product Support Lifecycle Policy, which provides information on product support policies.
Publication Status
Released: NOT RELEASED
Updated: Monday, June 24, 2024