HP Arcsight Smartconnector Supported Products Data Sheet
Total Page:16
File Type:pdf, Size:1020Kb
Data sheet HP ArcSight SmartConnector supported products The HP ArcSight library of out-of-the-box SmartConnectors provides source-optimized collection for leading security commercial products. These products span the entire stack of event-generating source types, from network and security devices to databases and enterprise applications. SmartConnectors are the default listing in this document. In addition to SmartConnectors developed and maintained by HP ArcSight, we test and certify the following connector types through our Technology Alliances Program: • Common event format (CEF) Certified—helps ensure event information is captured properly in the CEF • Action Certified—allows for control of a vendor’s technology from within the HP ArcSight Console Common event format are in bold below and Action are Italicized. If they have both they are bold and Italicized. HP ArcSight SmartConnector supported Application security platform for installation • Arxan GuardIT • CentOS-6.5, 6.6, and 7.0 • Bit9 + Carbon Black Security Platform • Microsoft® Windows Server® 2008 • CA Layer 7 SecureSpan/CloudSpan SP2 32/64-bit Gateway • Microsoft Windows Server 2008 • Intralinks VIA R2 SP1 64-bit • McAfee Application Control (Solidcore) • Microsoft Windows Server 2012 • RSA Silver Tail Systems Forensics Standard 64-bit, R2 64-bit • Red Hat® Enterprise Linux® (RHEL) Clinical/Healthcare applications 6.4 64-bit • FairWarning • SUSE Linux 11 Enterprise Server 64-bit • Oracle Solaris 10 64-bit, 11 32-bit Cloud • IBM AIX version 7.1 64-bit • Box • CloudPassage Halo Anti-virus/Anti-spam • FlexConnector for REST • F-Secure Anti-Virus • Zscaler Nanolog Streaming Service (NSS) • Kaspersky Anti-Virus • McAfee® VirusScan Enterprise Content security • Sophos • Gemalto (Safenet) eSafe Gateway • Symantec Endpoint Protection Manager • Barracuda (NetContinuum Web Firewall) (SEPM) DB SEP 12 • McAfee Email and Web Security Appliance • Symantec Mail Security for Microsoft • McAfee Web Gateway Exchange • Proofpoint Enterprise Protection and • Trend Micro (TM) OfficeScan (Control Enterprise Privacy Manager and TM Control Manager • Puresight Content Filter Database [DB]) • Trend Micro Control Manager • Trend Micro InterScan Messaging Security Applications (Control Manager) • IBM WebSphere • Trend Micro InterScan Web Security • iT-CUBE agileSI SAP® (Control Manager) • Oracle WebLogic Server (BEA) • SAP enterprise resource planning (ERP) • Microsoft SharePoint Server DB Data sheet | HP ArcSight SmartConnector supported products Database Activity Monitoring (DAM)/ IDS/IPS—network-based DB security • Broadweb NetKeeper • Trustwave Application Security DbProtect • Bro IDS • IBM InfoSphere Guardium • Bro IDS NG File • Imperva SecureSphere • Cisco Secure IPS • McAfee Sentrigo Hedgehog • Extreme Networks Enterasys Dragon (Enterprise and vPatch) • HP TippingPoint Security Management System (SMS) Database • IBM Proventia IPS Appliance (SiteProtector) • IBM DB2 • Juniper Networks IDP (NetScreen) • IBM DB2 UDB Audit File • McAfee Network Security Manager • IBM DB2 UDB Audit File, Multiple Instance (Intru Shield) • Microsoft SQL • NitroSecurity IPS • Oracle Audit DB • Radware DefensePro • Oracle Audit Vault • Snort • Oracle Audit Syslog • Cisco Sourcefire Intrusion Sensor • Oracle Audit XML11gR2 • Cisco Sourcefire Defense eStreamer • Sybase Adaptive Server Enterprise (Policy Violation) • Cisco Sourcefire Defense Center eStreamer Data leak prevention • Cisco Sourcefire Real-time Network • Fidelis Cybersecurity XPS Awareness (RNA) Sensor • GTB Inspector • McAfee Host Data Loss Prevention IDM, IAM, and identity security Endpoints (HDLP) • RSA Aveksa • Symantec DLP (Vontu) • BeyondTrust PowerBroker • Verdasys Digital Guardian • Cisco Secure Access Control Server (ACS) • CyberArk Privileged Identity Data security Management (PIM) Suite • CyberArk Inter-Business Vault • CyberArk Privileged Session Management • CyberArk Sensitive Document Vault (PSM) Suite • Gemalto (Safenet) Ingrian • Dell ChangeAuditor DB (Quest) • HP Atalla Network Security • IBM Tivoli Access Manager Processor (NSP) • Juniper Steel-Belted Radius (SBR) • JBoss Security Auditing File • Lieberman Software Enterprise Random • Vormetric Data Firewall Password Manager (ERPM) • Vormetric Data Security Manager • Microsoft Active Directory • Zettaset BDEncrypt • Microsoft Forefront • Microsoft Forefront DB Firewall • Microsoft Network Policy Server • Check Point FW-1 • Netwrix Auditor • Cisco PIX Firewall • Novell Nsure Audit • Cisco PIX/ASA Syslog • ObserveIT Enterprise • Juniper Networks (Altor Networks • Oracle Sun ONE Directory Server Virtual Firewall) • VMware® PacketMotion PacketSentry • Juniper Network Security Manager • RSA Authentication Manager (NetScreen) • Securonix RTI-Risk and Threat • Juniper Network Security Manager Syslog Intelligence • Juniper Networks Firewall and VPN • SpectorSoft Spector 360 Export Service • McAfee Enterprise Syslog • Thycotic Secret Server Intrusion Detection System and Intrusion Prevention System—host-based • IBM BlackICE Server Protection (IBM Security SiteProtector System) • Symantec Critical System Protection Database • Tripwire Enterprise Belden (Tripwire) 2 Data sheet | HP ArcSight SmartConnector supported products Integrated security Malware detection • Barracuda Spam Firewall • AhnLab Malware Defense System (MDS) • Cisco ASA 5500 • Damballa CSP • Fortinet FortiGate • Damballa Failsafe • HP TippingPoint Next-Generation • FireEye Malware Protection Firewall (NGFW) System (MPS) • Palo Alto Networks PAN-OS • FireEye Mandiant Intelligent Response • Secure Computing Sidewinder • Guidance EnCase • Dell SonicWALL • HBGary Active Defense • Stonesoft StoneGate • Lastline Enterprise • TaaSera TaaS NetAnalyzer IT operations • HP Operations Manager (OM and OMi) Network access control • HP OpenView Operations (OVO) • ForeScout CounterACT • Portnox Portnox Log consolidation and analysis • Dell InTrust (fka Aelita Event Manager [AEM]) Network behavior anomaly • Enterprise IT Security SF-RiskSaver • Arbor Networks Peakflow • LOGbinder SP • Lancope StealthWatch • Qualys QualysGuard File, version 7.1 • Qosmos DeepFlow Security Mail filtering Network forensics • Cisco IronPort Email Security Appliance • Narus nSystem • McAfee Email Gateway (Secure • NIKSUN NetDetector Computing IronMail) • RSA NetWitness • McAfee Security for Email Servers • Fidelis Cybersecurity (Access Data) CIRT (GroupShield) • Symantec Messaging Gateway Network management (Mail Security 8200 Series) • Cisco Wireless LAN Controller Syslog • HP Network Node Manager i SNMP Mainframe • Lumeta Enterprise Situational • CA Top Secret Intelligence (ESI) • IBM OS/390 (NVAS) • Lumeta IPsonar • IBM OS/390 (SDSF) • IBM z/OS System Log Network monitoring • IBM eServer iSeries Audit Journal File • ISC DHCP • Helpsystems PowerTech Interact • ISC BIND • Type80 SMA_RT for RACF • Microsoft Operations Manager DB (MOM) • Type80 SMA_RT for CA Top Secret • Microsoft System Center Operations • IBM AS/400 Manager (SCOM) DB • Microsoft System Center Configuration Mail server Manager DB • IBM Lotus Notes Domino Enterprise Server • Microsoft DHCP • Microsoft Exchange • Microsoft DNS • Microsoft Exchange PowerShell • Microsoft WINS • Microsoft Forefront for Exchange Server • Microsoft Forefront Protection Server Network traffic analysis Management Console DB • Cisco NetFlow/Flexible NetFlow • NetScout nGenius • FireEye nPulse Hammerhead • QoSient Argus • InMon sFlow® • Blue Coat Solera Networks DeepSee • TCPdump Network traffic management • Cisco Distributed Director for Cisco 4500 • Bro IDS 3 Data sheet | HP ArcSight SmartConnector supported products Operating systems Virtualization • IBM AIX Operating System • CounterTack Event Horizon • HP OpenVMS • VMware ESX/ESXi Server • HP-UX Operating System • VMware Virtual Center • HP-UX Syslog, version 11i v3 • Microsoft Windows 7/NT/2000/2003/ VPN XP/2008 Server/Vista • Check Point VPN-1 • Microsoft Windows® Event Log—unified, • Cisco VPN Concentrator SQL Server 2012 for SQL Server audit • Citrix® NetScaler • Red Hat Linux • Juniper/NetScreen (Neoteris) SSL VPN • Snare for Microsoft Windows • Nortel Contivity Extranet Switch • Solaris Basic Security module (BSM) • UNIX® Vulnerability assessment • SaberNet NTSyslog • eEye REM Security Management Console • HP NonStop servers (XYPRO • eEye Retina Network Security Scanner Merged Audit) • Harris STAT Scanner • IBM Internet Scanner Packet capture • McAfee Vulnerability Manager (FoundScan) • Ixia Anue Net Tool Optimizer • nCircle IP360 Device Profiler • nCircle IP360 Threat Monitor Physical systems/security • Nmap • RedCloud (PlaSec) • Open Vulnerability and Assessment Language (OVAL) Standard Policy management • QualysGuard • McAfee Policy Auditor • Rapid 7 Nexpose • NetIQ Security Manager • Tenable Nessus • SAINT Vulnerability Scanner Router • Cisco Router Web cache • Juniper Router (JUNOS) • Blue Coat Proxy SG Series • HP H3C Comware Platform • Microsoft Internet Security and Acceleration (ISA) Security management • Squid Web Proxy Cache • Enterasys Dragon Server • IBM SiteProtector Web filtering • iSIGHT ThreatScape API • Cisco IronPort Web Security Appliance • Lookingglass ScoutVision • Websense Web Security Suite • Malcovery MRTI • McAfee ePolicy Orchestrator (ePO) Web server • McAfee Network Security Manager DB • Apache • McAfee Rogue System Detection (via ePO) • Microsoft Internet Information Services (IIS) • Microsoft Audit Collection Services • Oracle Sun ONE • Symantec Enterprise Security Manager (ESM) Wireless • AirDefense Guard Storage • Fluke Network