3. Advanced Services
• Use Case design/ Content Authoring
– Creating/designing ESM content such rules,
activelists, trends, reports to achieve specific
business objectives
– Efficient ESM investigation management through
the use of cases
4. Best Practice
• Create a process to ensure all devices to be
monitored will send events to ArcSight
– i.e. For Windows Smartconnectors, please make
sure you add servers manually whenever a new
server is commissioned.
• Establish a case consolidation method
• Establish a good naming convention for cases
5. Key Differentiator
• Not just focused on BaseEvents (Device logs) but also on
arcsight internal events to leverage ESM correlation
potential
• Highly skilled in data analysis using “Data about your data”
• Experts in different platforms: OS/Network/Apps
• Experienced with most IT security software available.
• Worked for Infosec team of Security Companies: Trend
Micro and Mcafee (now INTEL)
• Focused on Security and Compliance (i.e. PCI-DSS)
• Experienced in Open-Source
6. Sample Configuration
Use case: Event Feed Monitoring
- Tracking event input from monitored devices
- Detecting devices that stoppped sending events
for investigation
* Use TTL or Event Expiry in ActiveLists