Respected Contributor.
Respected Contributor.

Arcsight Rules, Dashboards & Correlation

We need your support to learn about following grey areas.


  • Reading Incident logs & Event Categorization.
  • Complex Queries & Active channel creation.
  • Rules & Reporting
  • Correlation & Correlation Rule
  • Developing Adhoc rules
  • Developing Use Cases
  • Creating Active list & Session Lists
  • Creating Alerts & Notification
  • Finding scope for Rule creation from alert.
  • Generate Data monitors & Dashboards.
  • Asset Modeling

Any training material, docs or mentor ship available on the above topics?

Labels (1)
1 Reply
Acclaimed Contributor.
Acclaimed Contributor.

Re: Arcsight Rules, Dashboards & Correlation

I would encourage you to read the document below:

This is an excellent document that runs through each of these points and explains what they are and what they do. So I would really recommend that you take a look at this. Additionally, not sure what you mean by 'support' - this is a sophisticated area and you can do a lot with each of the points you have raised.

I would point you to some videos that should help:

But I need to update it - there are some more videos here:

Paul Brettle - YouTube

The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.