Micro Focus Arcsight Command Center User's Guide
Total Page:16
File Type:pdf, Size:1020Kb
Micro Focus Security ArcSight Command Center Software Version: 7.0 Patch 1 User's Guide Document Release Date: August 16, 2018 Software Release Date: August 16, 2018 User's Guide Legal Notices Warranty The only warranties for products and services of Micro Focus and its affiliates and licensors (“Micro Focus”) are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. Micro Focus shall not be liable for technical or editorial errors or omissions contained herein. The information contained herein is subject to change without notice. Restricted Rights Legend Confidential computer software. Except as specifically indicated otherwise, a valid license from Micro Focus is required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license. Copyright Notice © Copyright 2001-2018 Micro Focus or one of its affiliates. Trademark Notices Adobe™ is a trademark of Adobe Systems Incorporated. Microsoft® and Windows® are U.S. registered trademarks of Microsoft Corporation. UNIX® is a registered trademark of The Open Group. Support Contact Information Phone A list of phone numbers is available on the Technical Support Page: https://softwaresupport.softwaregrp.com/support-contact-information Support Web Site https://softwaresupport.softwaregrp.com/ ArcSight Product Documentation https://community.softwaregrp.com/t5/ArcSight-Product-Documentation/ct- p/productdocs Micro Focus Command Center (7.0 Patch 1) Page 2 of 216 Contents Chapter 1: Welcome to the ArcSight Command Center 10 Starting the ArcSight Command Center 10 Configuring Your Browser 10 Launching ArcSight Command Center 10 Logging in to ArcSight Command Center 11 Basic Navigation 12 Using the Site Map 12 Monitoring Usage Metrics (Stats) 13 Chapter 2: Viewing System Information 14 Managing Dashlets in the Dashboard Page 14 Adding a Data Monitor Dashlet to the Dashboards Page 14 Adding the My Cases Dashlet to the Dashboard Page 15 Adding My Dashboards to the Dashboard Page 16 Rearrange ArcSight Command Center Dashboard If Charts and Tables Overlap 17 Adding My Notifications to the Dashboards Page 17 Adding a Query Viewer to the Dashboards Page 18 Changing the Dashboards Layout 19 Managing Dashboards in the Dashboard Navigator Page 19 Viewing Dashboards in the Dashboard Navigator 19 Navigate from a Dashboard to a Channel in a Data Monitor 21 Specifying a Dashlet Chart Type 22 Downloading a Dashlet to a CSV File 25 Viewing Details for Events in a Last N Events Data Monitor 25 Using the Security Operation Center (SOC) Dashboard 27 Using the Cluster View Dashboard 28 Distributed Correlation Stats 28 Cluster 29 Details and Metrics for Individual Services 30 Audit Event Lists 31 Using the SOC Manager 31 Case Metrics 32 Analysts 34 Server Property Settings for the SOC Manager Dashboards 35 Micro Focus Command Center (7.0 Patch 1) Page 3 of 216 User's Guide Chapter 3: Monitoring Events Through Active Channels 37 Viewing Events On an Active Channel 38 Viewing a Channel Condition Summary 40 Viewing the Event Priority for a Channel 40 Evaluate the Network Route of a Event in a Channel 41 Accessing Integration Commands from an Event List 44 Accessing ArcSight Investigate or ArcSight Investigate Search from an Event List 45 About the Active Channel Header 46 Using the Active Channel Radar 48 Annotating an Event 49 Viewing Additional Event Information 50 Viewing Event Details 50 Viewing Event Annotation History 51 Viewing Event Payload 52 Managing Channels 52 Creating an Event Channel 52 Specifying Columns For the Active Channel Event List 54 Specifying Filter Conditions for an Active Channel 55 Creating a Channel Based on an Event Attribute 60 Editing an Event Channel 61 Deleting an Event Channel 63 Copying an Event Channel 64 Adding an Event to a Case 64 Marking an Event as Reviewed 65 Visualizing an Event Graphically 66 Chapter 4: Searching for Events in the ArcSight Command Center 68 The Need to Search for Events 68 The Process of Searching for Events 68 Simple Query Example 69 Query Example Using a Chart 69 Elements of a Search Query 70 Query Expressions 70 Search Expressions 71 Keyword Search (Full-Text Search) 71 Field-Based Search 74 Micro Focus Command Center (7.0 Patch 1) Page 4 of 216 User's Guide Searching Internet Protocol (IP) Addresses 78 Searching Media Access Control (MAC) Address 79 Search Operators 79 Time Range 79 Fieldsets 81 Creating Custom Fieldsets 82 Constraints 83 Using the Advanced Search Tool 92 Accessing Advanced Search 92 Nested Conditions 94 Alternate Views for Query Building in Advanced Search 95 Search Helper 96 Autocomplete 97 Search History 98 Search Operator History 98 Examples 98 Usage 98 Suggested Next Operators 99 Help 99 Searching for Events 99 Granting Access to Search Operations and Event Filters 101 Advanced Search Options 102 Searching Peers (Distributed Search) 102 Tuning Search Performance 102 Understanding the Search Results Display 103 User-defined Fields in Search Results 104 Viewing Search Results Using Fieldsets 105 Using the Histogram 105 Multi-line Data Display 106 Auto Updating Search Results 106 Chart Drill Down 107 Field Summary 108 Understanding Field Summary 108 Refining and Charting a Search from Field Summary 110 Adding Search Results to a Case 112 Exporting Search Results 112 Example PDF output 114 Scheduling an Export Operation 115 Saved Queries (Search Filters and Saved Searches) 116 Micro Focus Command Center (7.0 Patch 1) Page 5 of 216 User's Guide Saving a Query 116 Using a Search Filter or a Saved Search 117 Predefined Search Filters 118 Indexing 120 Full-text Indexing (Keyword Indexing) 120 Field-based Indexing 120 Chapter 5: Using Reports 121 Running and Viewing Reports 121 Report Parameters 122 Archived Reports 124 Deleting Archived Reports 125 Chapter 6: Cases 126 Case Navigation and Features 126 Creating or Editing a Case 127 Case Editor Initial Tab 127 Case Editor Follow Up Tab 131 Case Editor Final Tab 131 Case Editor Events Tab 133 Case Editor Attachments Tab 133 Case Editor Notes Tab 134 Granting Permission to Delete Cases 134 Deleting a Case 135 Viewing Notes and Updates in Case History 135 Viewing Case Details 135 Case Management in the ArcSight Console 136 Chapter 7: Applications 137 Chapter 8: Administration Configuration 138 Content Management 138 Planning for Content Management 139 Content Management Tabs 139 Packages Tab 139 Subscribers Tab 140 Schedule Tab 141 Micro Focus Command Center (7.0 Patch 1) Page 6 of 216 User's Guide Pushing Content Packages 141 Pushing a Package Automatically 141 Editing an Automatic Push Schedule 142 Pushing a Package Manually 142 Best Practices for Content Management 142 Storage and Archive 143 Overview 144 Storage 145 Storage Groups 147 Turning Archiving On and Off 148 Setting the Time to Archive Storage Groups 148 Adding a Storage Group 149 Editing a Storage Group 150 Allocating Storage Volume Size 150 Storage Mapping 152 Adding a Storage Mapping 152 Editing a Storage Mapping 153 Deleting a Storage Mapping 153 Alerts 154 Archive Jobs 154 Archives 155 Statuses and Actions 156 Filtering the List of Archives 157 Creating an Archive Manually 158 Scheduling an Archive 158 Making an Offline Archive Searchable or Unsearchable 158 Canceling an Action in Progress 159 Archive Storage Space 159 Moving Archives to a New Location 159 Backing Up Your Archive Configuration 160 Search Filters 160 Granting Access to Search Filter Operations 160 Managing Search Filters 161 Saved Searches 162 Granting Access to Saved Search Operations 162 Managing Saved Searches 163 Scheduled Searches 164 Granting Access to Scheduled Search Operations 164 Managing Scheduled Searches 165 Currently Running Scheduled Searches 168 Micro Focus Command Center (7.0 Patch 1) Page 7 of 216 User's Guide Ending Currently Running Searches 168 Finished Searches 168 Saved Search Files 168 Search 169 Tuning Search Options 169 Managing Fieldsets 171 Granting Access to Fieldset Operations 172 Viewing the Default Fields 172 Currently Running Tasks 173 Ending Currently Running Tasks 174 Peers 174 Configuring Peers 174 Guidelines for Configuring Peers 175 To Enable Peering 176 Authenticating Peers 176 Selecting a Peer Authentication Method 177 Authenticating a Peer 177 Adding and Deleting Peer Relationships 177 Adding a Peer 177 Deleting a Peer 179 Granting Access to Peer Operations 179 Log Retrieval 180 License 181 Appendix A: Search Operators 182 cef (Deprecated) 182 chart 183 Aggregation Functions 185 Multi-Series Charts 186 The Span Function 186 dedup 189 eval 190 extract 191 fields 193 head 194 keys 194 rare 196 Micro Focus Command Center (7.0 Patch 1) Page 8 of 216 User's Guide regex 197 rename 197 replace 199 rex 201 sort 203 tail 204 top 204 transaction 205 where 207 Appendix B: Using the Rex Operator 209 Syntax of the rex Operator 209 Understanding the rex Operator Syntax 209 Creating a rex Expression Manually 210 Appendix C: Frequently Asked Questions 212 What happens if I'm investigating a channel that has event fields that are not supported in Command Center? 212 Can I change the default start time and end time for an event channel? 212 What do I do if a channel is taking long to load? 213 How many channels can I have open at one time? 213 What fields are supported in Command Center channels? 213 Does Command Center support non-ASCII payload data? 214 How do I get my ArcSight Marketplace credentials? 214 Why are channels not current in a new ESM session? 214 Does the change to or from Daylight Savings Time effect an open active channel? 214 Why does the right end of the top menu bar appear overlapped? 215 Send Documentation Feedback 216 About this PDF Version of Online Help This document is a PDF version of the online help.