
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi All,
I'm very new to ArcSight, I had pretty confused when its highly recommended to use Trends.
Can anyone please help me regarding this !!!
Regards
SHINEJ
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Shinej.
Primary Trends is good to use when you need summary information about something for long period (few days, weeks, months). This information are static (you don't have option to add some field, you must create new trend). Most of users call trends snapshots but it not exactly right. Trends can be snapshots (based on assets, cases and notifications) and interval (summary based on events for defined time) You can create report or another query based on the trend. It is really fast to generate report from trends. Trend is created in specific period (hourly, daily) and it is good to schedule them to time when ArcSight isn't under the heavy load.
Good source of information is ESM 101 (site 95 of current 6.8c).

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Trends gather event data over time period , which helps identify, any security threats ,worm outbreaks, monitoring the incident life cycle,it can be used to monitor any network devices, operating systems,
asset activity by business role etc..
In an nut shell , its is used to apply the business logic over the
resources based on his historical behavior

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Shinej.
Primary Trends is good to use when you need summary information about something for long period (few days, weeks, months). This information are static (you don't have option to add some field, you must create new trend). Most of users call trends snapshots but it not exactly right. Trends can be snapshots (based on assets, cases and notifications) and interval (summary based on events for defined time) You can create report or another query based on the trend. It is really fast to generate report from trends. Trend is created in specific period (hourly, daily) and it is good to schedule them to time when ArcSight isn't under the heavy load.
Good source of information is ESM 101 (site 95 of current 6.8c).

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks Jan Odzgan for the detailed explanation