Arcsight Platform 24.2 Release Notes
Arcsight Platform 24.2 Release Notes
Legal Notices
Open Text Corporation
275 Frank Tompa Drive, Waterloo, Ontario, Canada, N2L 0A1
Copyright Notice
Copyright 2001 - 2024 Open Text.
The only warranties for products and services of Open Text and its affiliates and licensors (“Open Text”) are as may be
set forth in the express warranty statements accompanying such products and services. Nothing herein should be
construed as constituting an additional warranty. Open Text shall not be liable for technical or editorial errors or
omissions contained herein. The information contained herein is subject to change without notice.
Trademark Notices
“OpenText” and other Open Text trademarks and service marks are the property of Open Text or its affiliates. All other
trademarks or service marks are the property of their respective owners.
Contents
What's New 10
Introducing Multi-tenancy in the ArcSight Platform 10
Introduces the Ability to Create a Multi-tenant Environment 10
Benefits of Optics in a Multi-tenant Environment 11
For the ArcSight Platform Installer 11
Automated Off-Cloud Installation as a Non-Root User 11
Modification to Preparatory Steps for a Manual Off-Cloud Installation as a
Non-Root User 11
SSL Automatically Enabled 11
For Common Features in the ArcSight Platform 12
For Documentation 12
For Search 12
For the Reports Portal 13
For ArcSight Recon 16
Introduces Appliances for Recon 16
Introduces the Compliance Insight Pack for NERC 16
For SOAR 17
New Integration Plug-ins for SOAR 17
Enhancements 18
End of Support Announcements 18
ArcSight Dashboard and Widget SDK 19
Collectors and Connectors in Transformation Hub (CTH) 19
Technical Requirements 20
Downloading Files 20
Download the Installation Files 21
Understanding the Files to Download 21
Downloading and Verifying the Installation Files 24
Download Content Packages 25
Known Issues 25
Known Issues Related to ArcMC 25
26
736019 — Selecting a value for ArcMC Container Memory Limit Returns an
unformatted screen error 26
609152— CEF Routing Rule with Numeric Test May Result in Unintended
Events in Destination Topic 51
409228 — Schema Registry Instances May Be Allocated to Single Worker
Node 51
377141 — Event Integrity Enablement Stops Enrichment Stream Processor
Pods 54
Resolved Issues 54
Resolved Issues Related to Upgrade 54
876045 — Upgrade Process Previously Could Cause Data Loss by Changing
Retention Value to One Month 54
Resolved Issues Related to Intelligence 55
729040 — SearchManager Pods Fail Due to the Absence of Spacing in the
Elasticsearch Data Retention Period Value 55
611096 — Analytics Fails to Load Data Sources Except for AD and Proxy 55
Resolved Issues Related to Reports Portal 56
779004 — VPM Conditions/Triggers are now Being Applied for Scheduled
Dashboards 56
773027 — Restored Ability to Specify Time Ranges for Custom Reports and
Dashboards Because the Enter Parameters Modal is not Displayed 56
566085 — Network Chart Data are No Longer Presented in Portions and
Cut 56
Resolved Issues Related to Search 56
733209 — Scheduled Searches no Longer Display an Error When You Try to
Load a Field Summary on a Completed Run 57
616090 — For System Search Queries, #SSH Authentication No Longer
Generates an Error 57
608098 — Certain top/bottom Queries and Fields that Begin With "Device"
no Longer Fail 57
Resolved Issues Related to SOAR 58
591118 - Enrichment History - Sort By Capability And Status Functionality
Does not Sort By Alphabetical Order 58
655004 - SOAR FortiAnalyzer Plugin Should Accept Dynamic Ports 58
724037 - Enhancement - SOAR Should Support Updating User's Email
Address and Username When Changed in FUM 59
719017 - Proxy Option Missing in SMTP Mail Server Integration
Configuration 59
737015 - API Documentation soar-api/js-api-doc Search Does Not Work 59
Component Version
The documentation for this product is available on the ArcSight documentation website in
HTML and PDF formats. If you have suggestions for documentation improvements, click
comment or support on this topic at the bottom of any page in the HTML version of the
documentation posted on the ArcSight Platform CE Documentation page or the
documentation pages for the included products.
What's New
This release includes enhancements to the following capabilities, components, and features:
The links below for the Administrator's Guide for ArcSight Platform direct you to the off-cloud
deployment version of the guide. You can find the same topics in the guides corresponding to
the following deployment environments:
l AWS
l Azure
l Google Cloud
Optics are available only when Multi-tenancy is enabled and ArcSight ESM integrated with the
Platform.
For Documentation
With this release, the single ArcSight Platform Administrator's Guide has been divided into four
guides, one corresponding to each deployment type: Off-Cloud, Azure, AWS, and GCP.
Instructions in each guide apply only to installation and maintenance of the Platform on the
specified deployment type. (The unified guide has been discontinued.)
The new guides are located here:
https://wwwtest.microfocus.com/documentation/arcsight/arcsight-platform-24.2/
For Search
This release includes the following enhancements and changes for the Search feature:
based on the specified fieldset for the search. Please note the export process limits the file to
one million event records.
Note: Certain dashboards in this package require ArcSight ESM and ArcSight ESM Unified NERC
CIP to populate.
Each of the dashboards below has been organized by their corresponding NERC control
number, such as 005.
CIP Overview– Executive Summary NERC Compliance Provides a color-coded status overview of
Overview NERC CIP-related alerts reported in the
organization. Click each widget to view a
drill-down dashboard with more information
about alerts. NERC Compliance Overview
refreshes every 5 minutes with real-time
data from the ArcSight Forwarding
Connector.
Note: This dashboard requires ArcSight ESM
Unified NERC CIP to populate.
CIP-002-6 Cyber Security: BES Cyber New Devices Helps you track new device activity.
System Categorization
CIP-005-7 Cyber Security: Electronic Traffic Anomaly Helps you identify anomalies in network
Security Perimeter(s) traffic.
CIP-007-6 Cyber Security: System Login Activity Overview Provides an overview of login activity. The
Security Management table shows the details of the event, and
each event will take you to the Event
Inspector. You can also click Open in Search
and it will take you to the search page and
loads the categoryBehavior =
/Authentication/Verify query with the same
time that the dashboard was run.
CIP-008-6 Cyber Security: Incident Attack and Suspicious Displays an overall view of the attackers,
Reporting and Response Planning Activity Overview their techniques, and targets.
For SOAR
This release includes the following enhancements and changes for SOAR functionality:
l New Integration Plug-ins for SOAR
l " Enhancements" on the next page
Amazon AWS CloudTrail This integration plug-in has the following enrichment capabilities:
l List Trails
l Get Trail
l Create Trail
l Delete Trail
l Start Logging
l Stop Logging
l Get Trail Status
l Lookup Events
l List Queries
Cisco SecureX This integration plug-in has the following enrichment capabilities:
l Get Observable Details
l Get Observable Score
l Get Event Details
l Get Threat Context (Targets)
l Respond observable
Cofense Triage This integration plug-in has the following enrichment capabilities:
l Get URL Details
l Get Domain Details
l Get Report Details
l List Report Attachments
l Download Attachment Payload
l Get Reporter Details
l Update Report Category
l List Threat Indicators
l Get Threat Indicator Details
New Team Cymru This integration plug-in has the following enrichment capabilities:
l Single Lookup Hash Query
l Bulk Lookup Hash Query
OpenText Network Detection and Response This integration plug-in has the following enrichment capabilities:
l List Alerts
l Get Alert Details
l Get SmartPcap
l List Meta Data Activity
ServiceNow CMDB This integration plug-in has the following enrichment capabilities:
l List Assets
l Get Asset by ID
l Update Asset Tag
Enhancements
l Multi-Tenancy for MSSP-SOAR
With this release, ArcSight Platforms supports Multi-tenancy wherein, you can create and
manage multiple tenants.
l Installation Update for SOAR
Up to the previous releases, SOAR used to be bundled with Core and would be
automatically installed when Core would be installed. With this release, SOAR is now an
independent capability and has its own installation file. If you need SOAR in your
environment, ensure that you download the installation package specified for SOAR in the
Understanding the Files to Download section and proceed to install SOAR as a separate
capability.
Enhancements Page 18 of 63
ArcSight Platform CE Release Notes
Technical Requirements
For more information about the software and hardware requirements required for a successful
deployment, see the Technical Requirements for ArcSight Platform. These Technical
Requirements include guidance for the size of your environment based on expected workload.
OpenText recommends the tested platforms listed in this document.
Customers running on platforms not provided in the Technical Requirements or with untested
configurations will be supported until the point OpenText determines the root cause is the
untested platform or configuration. According to the standard defect- handling policies,
OpenText will prioritize and fix issues we can reproduce on the tested platforms.
Downloading Files
You can download the required installation or content packages.
All Deployments - Images esm-1.6.0-5.tar Contains the images for deploying ArcSight
ESM Web App
Evolving security needs imply the renewal of certificates for the signature verification
procedure. To ensure a successful verification of your product signature, download the
latest public keys file before proceeding with the verification process (step 1 of the Get the
Public Keys procedure).
OpenText provides a digital public key that is used to verify that the software you
downloaded from the OpenText software entitlement site is indeed from OpenText and
has not been tampered with by a third party. For more information and instructions on
validating the downloaded software, visit the OpenText Code Signing site. If you discover a
file does not match its corresponding signature (.sig), attempt the download again in case
there was a file transfer error. If the problem persists, please contact OpenText Customer
Support.
Known Issues
These issues apply to common or several components in your ArcSight Platform deployment.
For more information about issues related to a specific product, please see that product's
release notes.
OpenText strives to ensure that our products provide quality solutions for your enterprise
software needs. If you need assistance with any issue, visit OpenText Support, and then select
the appropriate product category.
All issues listed in this section belong to the OCTCR33I repository, unless otherwise noted.
The output of the command should show a value of 4/4 (the pod's READY state) and of
Running (the pod's STATUS) for the fusion-arcmc-web-app pod.
3. Go to the ITOM Management portal and click on the 3 dots menu. Select the Reconfigure
option.
4. Go to ArcMC Configuration and select a value for ArcMC Container Memory Limit (4GB,
5GB, 6GB, 7GB or 8GB).
5. Click the Save button.
Page 26 of 63
ArcSight Platform CE Release Notes
cd /mnt/efs/<nfs_folder>/
$ kubectl delete pods -n $(kubectl get namespaces | grep arcsight | cut -d '
' -f1) $(kubectl get pods -n $(kubectl get namespaces | grep arcsight | cut
-d ' ' -f1) | grep arcmc | cut -d ' ' -f1)
mismatch can occur for a variety of reasons and can lead to confusion and difficulties for the
user in accessing and interpreting the log data.
Workaround: No known workaround for this release.
l "896079 — ESM Web App Loads Indefinitely When ESM Host is Not Configured in OMT"
below
l "899136 — After upgrading OMT from 24.1 to 24.2, the ESM Web App might not restart
properly on its own" below
896079 — ESM Web App Loads Indefinitely When ESM Host is Not Configured Page 29 of 63
ArcSight Platform CE Release Notes
As a result, analytics is unable to load the other data sources, such as Resource, Share, VPN,
and Repository.
Workaround: Perform the following steps to specify each data source for the data source
configuration:
1. Open a certified web browser.
2. Specify the following URL to log in to the OMT Management Portal: https://<omt_
masternode_hostname_or_virtual_ip_hostname>:5443.
3. Select Deployment > Deployments.
4. Click ... (Browse) on the far right and choose Reconfigure. A new screen will be opened in a
separate tab.
5. Click Intelligence.
6. In the Analytics Configuration - Database section, modify Database Loader Data Sources
field's value to ad,pxy,res,sh,vpn,repo.
616036 — If Not Already Logged into Fusion, the First Attempt to Log Directly Page 31 of 63
ArcSight Platform CE Release Notes
8. Click Update.
9. Restart the interset-api pods:
a. Launch a terminal session and log in to the master or worker node.
b. Execute the following command to retrieve the namespace:
399297 - Intelligence Search API Fails with a Timeout Error (esSocketTimeout Page 32 of 63
ArcSight Platform CE Release Notes
https://<virtual_FQDN>:5443
3. Click CLUSTER > Dashboard. You are redirected to the Kubernetes Dashboard.
4. In Namespace, search and select the arcsight-installer-xxxx namespace.
5. In Config and Storage, click Config Maps.
6. Click the filter icon, then search for investigator-default-yaml.
7. In the db-elasticsearch section of the YAML tab, modify the esSocketTimeout value based
on the data size.
For example, if the Intelligence search API takes 150 seconds to retrieve data from the
database, then ensure that you set the esSocketTimeout value to more than 150 seconds
to avoid the exception.
8. Click Update.
9. Restart the interset-api pods:
a. Launch a terminal session and log in to the master or worker node.
b. Execute the following command to retrieve the namespace:
401549 - Most Pods Enter into the CrashLoopBackOff State if the KeyStore Page 33 of 63
ArcSight Platform CE Release Notes
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
scale statefulset interset-logstash --replicas=0
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
edit configmaps logstash-config-pipeline
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
scale statefulset interset-logstash --replicas=<number_of_replicas>
614051 - Logstash Pod Fails on Data Ingestion in AWS Deployment When Using Page 34 of 63
ArcSight Platform CE Release Notes
613050 - Installer Does Not Validate the Value You Specify for
Elasticsearch Data Retention Period
Issue: In the OMT Management Portal > Configure/Deploy page > Intelligence > Elasticsearch
Configuration section, the installer does not validate the value you specify for the Elasticsearch
Data Retention Period field. The tool-tip for the Elasticsearch Data Retention Period field
suggests that you should specify a value greater than 30 for indices retention. However, there
is no validation preventing you from entering a value that is less than 30. If you specify a value
614047 - Changing the HDFS NameNode Does Not Terminate the Previous Page 35 of 63
ArcSight Platform CE Release Notes
that is less than 30, the value for Elasticsearch Data Retention Period will be set to the
minimum default value of 30 days.
Workaround: There is no workaround at this time.
Workaround: You must restart the Elasticsearch cluster to refresh the Elasticsearch
environment.
l 844085 — An Operation to Add a New Role or Group to a User Succeeds, But the UI Does
Not Update to Reflect the Change
l "750053 — Import Logger Status Does Not Update Correctly" on page 40
l 534015 — Autopass container crashing with exception: relation "mysequence" already
exists
l 470057 — Left Navigation Menu Items Do Not Reliably Display When Pods Restart or are
Unresponsive
l 411123 — Event Integrity Query Indicates Insufficient Disk Space (AWS/Azure)
l 112042 — Pods Might Not Run During Fusion Reinstall
Workaround: If this issue occurs, you should set up an SSH connection between the Logger and
the database. This workaround applies to an off-cloud deployment of the ArcSight Database on
a server running RHEL 9.2 as well as on an appliance for ArcSight Recon.
1. Log in to the database server:
l For an off-cloud deployment: Log in to the primary ArcSight Database node as a root
user.
l For a Recon appliance: Log in as an ArcSight user.
2. If your login credentials do not have the database administrator permissions, change to a
database admin user:
l For an off-cloud deployment: su - [dbadmin_username]
l For a Recon appliance: sudo su - [dbadmin_username]
3. To set up a SSH connection with the Logger, enter the following command:
898339 — AWS Fresh Installation Fails on EKS Later Than 1.28.3 Page 38 of 63
ArcSight Platform CE Release Notes
Workaround:
1. Attempt to re-run the upgrade.
2. If re-running the upgrade does not solve the problem, run the following command on
every node where the error occurs:
<OMT_HOME>/bin/kube-restart.sh
For example:
/opt/arcsight/kubernetes/bin/kube-restart.sh
firewall-cmd --add-forward
firewall-cmd --add-forward --permanent
firewall-cmd --add-interface cni0
firewall-cmd --add-interface cni0 --permanent
These steps are included into the arcsight-install --cmd upgrade command, so they're not
necessary with arcsight-install upgrades.
863005 — Upgrade to ArcSight 24.2 may fail with errors related to cluster Page 39 of 63
ArcSight Platform CE Release Notes
.. <> ...
844085 — An Operation to Add a New Role or Group to a User Succeeds, But Page 40 of 63
ArcSight Platform CE Release Notes
3. List the relations to see the flag, remove it and exit the psql with "\q" and ssh pod with
"exit"
4. Restart the autopass pod using kubectl delete pod, and then make sure the container
starts correctly with 2/2 Ready status.
898212 - InetSoft Logger Report Converter Tool Does Not Handle Custom Page 43 of 63
ArcSight Platform CE Release Notes
Workaround: Refresh the page to load the Contract & Usage page.
372067 — Contract & Usage Page Throws an Ingress Router Error and Does Page 44 of 63
ArcSight Platform CE Release Notes
Workaround: Ideally, the system should share Materialized Views (MVs), but if different
parameters are needed, different worksheets should be used.
Workaround: Reload the page. To prevent the issue, wait for search execution to finish, delete
that search, and create a new one.
837049 — Delete Scheduled Search Dialog Box is Missing the OpenText Page 46 of 63
ArcSight Platform CE Release Notes
766026 — User Preferences Drop-down Menus are Closed if You Click in the Page 47 of 63
ArcSight Platform CE Release Notes
609036 — Upgrade Issues: Searches That Use the "All Fields" Fieldset and the Page 48 of 63
ArcSight Platform CE Release Notes
113040 — CSV File Export Fails after You Change the Date and
Time Format
Issue: After modifying the date and time format in preferences, the CSV export function for
saved searches runs before the preference change fails.
Workaround: Run the scheduled search again, then save it. Select the CSV icon to download
the file
113040 — CSV File Export Fails after You Change the Date and Time Format Page 49 of 63
ArcSight Platform CE Release Notes
895045 — SOAR Permissions and Respond in Left Navigation is Shown Even Page 50 of 63
ArcSight Platform CE Release Notes
If the output shows all instances are running on the same worker node, Schema Registry must
be restarted to spread the instances across worker nodes.
2. Restart Schema Registry.
609152— CEF Routing Rule with Numeric Test May Result in Unintended Page 51 of 63
ArcSight Platform CE Release Notes
Verify restart has completed by waiting until all Schema Registry pods have a status of Running,
and a small age value of the minutes or seconds since you performed the restart.
After the restart completes, verify the instances are now running on different worker nodes.
In a multi-node scenario, a topic used internally by Schema Registry may get configured with
too few replicas, which reduces reliability and can make the registry fail during failover. Check
the topic's configuration to verify it has the proper replica count (replication factor).
3. In a multi-node deployment, identify the replica count for the topic "_schemas". Set the
topic to be used in later commands.
topic="_schemas"
5. If the replication factor is not 3, perform the following steps to change the
configuration: Get the list of brokers to set as replicas, including the topic's partition
leader. If the cluster has more than three brokers, limit the replicas to three.
topicfile=/tmp/topic.json
assignfile=/tmp/assign.json
printf '{"topics": [{"topic": "%s"}], "version":1}' $topic > $topicfile
kubectl cp $topicfile $namespace/th-kafka-0:$topicfile
kubectl -n $namespace exec th-kafka-0 -- kafka-reassign-partitions --broker-
list "$allbrokerids" --bootstrap-server th-kafka-svc:9092 --generate --
topics-to-move-json-file $topicfile > $assignfile
sed -i '1,/Proposed partition reassignment/d' $assignfile
409228 — Schema Registry Instances May Be Allocated to Single Worker Node Page 52 of 63
ArcSight Platform CE Release Notes
8. Verify the reassignment completes by running a verify command with the same input file.
9. Since the replicas have changed, run a preferred leader election for the topic's partition.
electfile=/tmp/election.json
printf '{"partitions": [{"topic": "%s","partition":0}]}\n' $topic >
$electfile
kubectl cp $electfile $namespace/th-kafka-0:$electfile
rm -f "$electfile"
kubectl exec -n $namespace th-kafka-0 -- kafka-leader-election --bootstrap-
server th-kafka-svc:9092 --election-type preferred --path-to-json-file
$electfile
Also in a multi-node scenario, an internal ArcSight topic may get configured with too few
replicas, which reduces reliability of Stream Processor metrics and can prevent ArcMC from
displaying the metrics. Check the topic's configuration to verify it has the proper replica count.
In a multi-node deployment, identify the replication factor for the topic "th-arcsight-avro-sp_
metrics".
10. Set the topic to be used in later commands.
409228 — Schema Registry Instances May Be Allocated to Single Worker Node Page 53 of 63
ArcSight Platform CE Release Notes
topic=th-arcsight-avro-sp_metrics
Repeat all of steps 4 and 5 above to check the topic and modify it if needed. The topic needs to
have the same replica count as the previous topic: three.
Resolved Issues
These issues apply to common or several components in your ArcSight Platform deploy. For
more information about issues related to a specific product, please see that product's release
notes, as applicable.
All issues listed in this section belong to the OCTCR33I repository, unless otherwise noted.
could erroneously purge data you wanted to retain. (This is because the data purge job runs at
midnight on the first day of each month.)
This issue occurred when the autopass pod was down but the fusion-search-web-app and
fusion-search-and-storage-web-app pods were running. (The autopass pod tells the system
whether you have a license that allows more than one month of storage, such as the ArcSight
Recon license.) A software update resolved the issue.
As a result, analytics is unable to load the other data sources, such as Resources, Share, VPN,
and Repository.
Fix: This issue has been resolved now.
733209 — Scheduled Searches no Longer Display an Error When You Try to Page 57 of 63
ArcSight Platform CE Release Notes
724037 - Enhancement - SOAR Should Support Updating User's Email Address Page 59 of 63
ArcSight Platform CE Release Notes
Contacting OpenText
For specific product issues, contact OpenText Support.
Additional technical information or advice is available from several sources:
l Product documentation, Knowledge Base articles, and videos.
l The OpenText Community pages.
Additional Documentation
The ArcSight Platform documentation library includes the following resources:
l Administrator's Guide for ArcSight Platform, which contains installation, user, and
deployment guidance for the ArcSight software products and components that you deploy
in the containerized platform.
See the guide that corresponds to your deployment:
o Administrator's Guide for the ArcSight Platform CE 24.2 - AWS Deployment
o Administrator's Guide for the ArcSight Platform CE 24.2 - Azure Deployment
o Administrator's Guide for the ArcSight Platform CE 24.2 - Google Cloud Deployment
o Administrator's Guide for the ArcSight Platform CE 24.2 - Off-Cloud Deployment
l Technical Requirements for ArcSight Platform, which provides information about the
hardware and software requirements and tuning guidelines for the ArcSight Platform and
the deployed capabilities.
l User’s Guide for ArcSight Platform, which is embedded in the product to provide both
context-sensitive Help and conceptual information.
l Product Support Lifecycle Policy, which provides information on product support policies.
Publication Status
Released: Wednesday, June 5, 2024
Updated: Tuesday, June 4, 2024