ArcSight & Ayehu eyeShare Automation - by We-Ankor
We, at We-Ankor (formerly We!), have started working with a company named Ayehu.
For those who are not familiar, Ayehu develop an extremely flexible automation framework called 'eyeShare' that can be used to automate anything, from simple scheduled routines to complex incident response procedures based on triggers.
We built a bi-directional integration between ArcSight and eyeShare that works as followed:
- A rule (any rule) is triggered at ArcSight.
- The rule sends an e-mail (or SNMP/Syslog/etc.) to eyeShare.
- When eyeShare receives that information, it parses the data, understands which rule was triggered, and starts a response procedure for according to a defined set of workflows that can be created and customized.
- When the response procedure is complete, or on selected stages along the way, it returns information back to ArcSight.
Using this automation, we were able to shorten incident response processes for many scenarios from days to minutes, freeing time for operators and analysts to investigate new information.
Please view the following presentation showing a few key concepts and use cases:
Feel free to contact me for more information.