UPDATE! The community will be go into read-only on April 19, 8am Pacific in preparation for migration on April 21. Read more.
UPDATE! The community will be go into read-only on April 19, 8am Pacific in preparation for migration on April 21.Read more.
Cadet 3rd Class
Cadet 3rd Class
329 views

Anonymizing forwarding logger data

Hi everyone,

for testing purposes I would like to send anonymized data from out Arcsight Logger to an ESM. To anonymize the data I would like to replace the following field with jabberish before forwarding it.

Hostname

Agent Zone Resource

Customer Resource

Agent Name

Device Host Name

Device Zone Resource

Attacker Hostname

Attacke Zone Resource

Attacker Asset Resource

Attacker Translated Zone Resource

Target Host Name

Target Zone Resource

Target Asset Resource

Target Translated Zone Resource

So far I've set up an CEF Forwarder to the ESM, which is working just fine. Though, I've not been able to find the location where the connector on the ESM where the connector is installed. When I'm able to locate these I should be able to alter the data, correct? I'm looking for someone who has configured the same or similar situation and would like to help me out.

Labels (3)
0 Likes
3 Replies
Absent Member.
Absent Member.

I think you are looking for the "fields to obfuscate" setting.

From your ESM Console Navigator > Connectors > loggerConnector > right click > Configure >default

Scroll down and you'll find the option under processing, you can only obfuscate string fields though, so heads up on that.

0 Likes
Cadet 3rd Class
Cadet 3rd Class

Thansk you for assisting me. It is close to what I'm looking for except I would like to replace the fields with different string instead of obfuscating them.

0 Likes
Absent Member.
Absent Member.

Wouldn't you be sending the same event over and over again then??

If you're looking to do that, you can use a replay(test alert) connector and you can customize exactly what the outgoing events looks like. The other option is to update the field mappings.

/current/user/agent/map/map.0.properties

set.event.flexString1

<whatever you want>

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.