Having problems with your account or logging in?
A lot of changes are happening in the community right now. Some may affect you. READ MORE HERE
AarushJ Super Contributor.
Super Contributor.
2998 views

SMB1 is disabled on servers integrated to ArcSight Smart Connector results in issue with logs

Jump to solution

Hello All,

As we are all aware of recently going Ramsomeware attack worldwide "WannaCry". It is been obserserved that SMB1 protocol version is vulnerable to kept it open so respective team has dissabled the SMB1 on the servers.

Which results in stopping the connection to host for data transfer from host device/server to Arcsight connector.

Currently we are facing frequent issues related to device non-reporting due the SMB1 is dissabled at the server.

Request to suggest alternative option to make the data transfer work and non-reporting issue.
Attaching the snapshot for the same.
Regards,
Anchal Jain
+918147106564

AJ
Labels (1)
1 Solution
4 Replies
stefan.oancea Outstanding Contributor.
Outstanding Contributor.

Re: SMB1 is disabled on servers integrated to ArcSight Sm...

Jump to solution

Hello Anchal,

I presume you are talking about the Windows Unified Connector? If so, the Unified has the limitation that it can only support SMBv1. As soon as you block SMBv1, you can expect the Connector not to be able to retrieve logs anymore.

The Windows Native however supports both SMBv2 and SMBv3. So I think that upgrading your connectors to Windows Native and only allowing SMBv2 or v3 on your servers should solve your issue. From the Windows Native Configuration Guide:smb.jpg

 

However, just patching the Windows Environment might be a better idea than totally disabling SMB protocol. I presume there are more services in the network using SMB and not only the ArcSight Connectors.

All the best,

Stefan

 

 

 

pbrettle Acclaimed Contributor.
Acclaimed Contributor.

Re: SMB1 is disabled on servers integrated to ArcSight Sm...

Jump to solution
Completely agree - the Windows Native Connector is the way forward (also called WINC). It is better, easier and simpler and supports the Microsoft way to collect data. Use it!
Highlighted
Arcsight_Logger_User Super Contributor.
Super Contributor.

Re: SMB1 is disabled on servers integrated to ArcSight Sm...

Jump to solution
Those who are using WUC on Linux have to move to WINC on Windows. Fantastic product roadmap by HPE.
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.