IBM SiteProtector version 3 and Arcsight 5.2 integration: getting events very slowly
I am managing an Arcsight implementation. We are using IBM SiteProtector version 3. The Arcsight connector connects to the database every 15 minutes and pulls events. We already had a SIEM tool which is collecting this data in real time by accessing the database every few seconds. I have checked the smart connector documentation and SiteProtector version 3 is not supported. Are there any workarounds to this problem? I have raised a feature enhancement request with support but have not heard from them.
I had a similar experiece with SiteProtector 2.9.
When I upgraded the Connector Software from 5.x to 6.x i noticed exactly the same - I couldn't be bothered to waste much time in investigating though, so I just rolled back to Connector (5.2.?) it was i believe. Worked like a charm.
Thanks for your message. We had initially started with version 5.x of the connector. HP upgraded the connector to 6.x without success. The strange thing is that the events that we are getting are complete but the connector is poling the SiteProtector database only every 15 minutes which apparently is not soon enough. Our other SIEM solution pols almost every 15 seconds. Can we adjust the pol timing and try collecting events? I have still not heard from HP support so am exploring all avenues. We cannot change the version of SiteProtector.
Hi Pranav Lal,
Were you able to get this issue resolved by chance? We are also experiencing the same symptoms, but we initially started with the connector version of 4.x and upgraded to 18.104.22.16895. I have to restart the connector to show current events, but unfortunately it will slow down rather quickly after a connector restart in any case. Any help is appreciated.
Thank you for the information. Unfortunately, Arcsight support states that it (SiteProtector 3.0) is not supported and allows me to request it as a future enhancement. I'd like to implement the parser override, but I don't have the parser nor instructions on how to accomplish this. Was there something particular that you had mentioned when dealing with the Arcsight support team so that that could assist you with the issue at hand?
No but we have a very large implementation therefore roped our project team into it. I am not sure what happened after that. I have already requested that enhancement. I was told that the solution will appear next month. This happened in December.
I don’t know what the protocol is here but I could ask if you like.
Thank you Pranav, I've provided this link to Arcsight support so hopefully they will be able to provide me that parser as well. If I don't get any resolution from them then I may come back here to ask for more of your assistance if this is OK.