Absent Member.
Absent Member.
14199 views

Device Status Monitoring Pack

Hey guys,

Appreciate that there are some threads that talk about Device Status Monitoring (DSM), but we have released a content pack to help you get started in ensuring that you always get your event logs. This is aimed more at people that are new to ArcSight and just getting started, as I'm sure that the more seasoned of you will already have something setup.

General Description

The success of any SIEM system relies on receiving events from the respective in scope source devices and servers. Without any events, the SIEM platform effectively becomes useless. Part of setting up a good SIEM system is creating mechanisms to ensure that these events are received and the most effective approach to do this is by using the Device Status Monitoring (DSM) capability built-in to the ArcSight platform.

This content pack utilises the DSM capability to track and alert on any event sources that stop sending events, so that you can take the appropriate action to re-establish the event flow. The pack also contains mechanisms to detect servers/devices that have potentially been removed from the network.

Other Information

+ Attached is the user guide, and the complete pack is available from our website http://www.edgeseven.com/resources.html.

+ This also ties into our blog (http://totalsiem.blogspot.com), where we are currently discussing the "Golden Rules of SIEM"

Hope you all find this useful ... please do provide feedback 😉

Labels (2)
Tags (3)
137 Replies
Absent Member.
Absent Member.

Hi Mark,

I'm Bob.

Can you please send me the package.

I really need it for my problem solving!

Email: hlog@ahnlab.com

Thank you!

0 Likes
Absent Member.
Absent Member.

I need the version that will work with ESM 5.0

Robin.Jackson@wellpoint.com

0 Likes
Commodore
Commodore

Superb

A++++++

Manoj S.
0 Likes
Commodore
Commodore

Dear Mark,

Could you please send me the Device Status Monitoring Pack @ hatem.metwally@mannai.com.qa

BR,

Hatem Metwally

0 Likes
Absent Member.
Absent Member.

Hi, Mark,

Could you please send me the device status monitoring pack to my email id Tajudeen.Abdulrashid@chemtura.com

Regards

Tajudeen

Mark Johnston wrote:

Hey guys,

Appreciate that there are some threads that talk about Device Status Monitoring (DSM), but we have released a content pack to help you get started in ensuring that you always get your event logs. This is aimed more at people that are new to ArcSight and just getting started, as I'm sure that the more seasoned of you will already have something setup.

General Description

The success of any SIEM system relies on receiving events from the respective in scope source devices and servers. Without any events, the SIEM platform effectively becomes useless. Part of setting up a good SIEM system is creating mechanisms to ensure that these events are received and the most effective approach to do this is by using the Device Status Monitoring (DSM) capability built-in to the ArcSight platform.

This content pack utilises the DSM capability to track and alert on any event sources that stop sending events, so that you can take the appropriate action to re-establish the event flow. The pack also contains mechanisms to detect servers/devices that have potentially been removed from the network.

Other Information

+ Attached is the user guide, and the complete pack is available from our website http://www.edgeseven.com/resources.html.

+ This also ties into our blog (http://totalsiem.blogspot.com), where we are currently discussing the "Golden Rules of SIEM"

Hope you all find this useful ... please do provide feedback 😉

0 Likes
Commodore
Commodore

Hello Tajudeen,

that links you provided are not working anymore. Can you share new one with us?

__
Solution Security Architect
0 Likes
Absent Member.
Absent Member.

fyi only

I just got the confirmation from HP support in Ticket ID 4651189492, that Connector DSM events are limited to 1000 entries only...

"/opt/arcsight/ArcSightSmartConnectors/current/bin/arcsight -quiet agentcommand -c status | grep "Device " | wc -l"

As per below the original wording from the ticket

Andro

###

Hi,

Thanks for the update. I have just confirmed that indeed that in the SmartConnector there is a hardcoded maximum limit in of devices for which DSM will be logged/sent. The limit is 1000 as you have observed. So if the connector is receiving events from 5000 devices only the first 1000 will have DSM enabled.

 

Regards

ArcSight Support

###

0 Likes
Fleet Admiral
Fleet Admiral

Andro,

what would be a sufficient number?

~ Ofer

0 Likes
Cadet 3rd Class Cadet 3rd Class
Cadet 3rd Class

hello people, I have the same problem as you, can not monitor the absence of events from devices on the connectors.

Could you send me the Device Status Monitoring Pack for email ?

rodrigo.curcino@ibest.com.br

Thank you for you help.

0 Likes

Hi Ofer, Do you have DSM pack? kindly email to me rajaasilah.hazwani@gmail.com

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.