Re: Setting up Arcsight/Tripwire



--On Tuesday, April 07, 2009 02:15:13 -0600 venkatesh.selvaraju@xxxxxxxxx wrote:

Dear All,

I was wondering if anyone has any standard rules and policies which can be
instantly deployed & added to Arcsight ESM for monitoring Windows, UNIX,
database and network devices. I understand the rules vary and are specific to
the OS and n/w devices. We have to setup the rules and commission Arcsight in
our company. If anyone has prior hands-on using Arcsight or if you have any
literature, please share. Also, if you have any docs on how to setup rules
on Tripwire tool for file integrity checking please share the information.
Thank you in advance.


Arcsight is an expensive product. Surely you got training and access to docs with your licenses? If you're just now deploying, Arcsight should be assisting you with that - especially your salesperson.

--
Paul Schmehl, Senior Infosec Analyst
As if it wasn't already obvious, my opinions
are my own and not those of my employer.
*******************************************
Check the headers before clicking on Reply.



Relevant Pages

  • Re: Setting up Arcsight/Tripwire
    ... Is SPLUNK also similar to ArcSight, as it also captures different logs ... UNIX, database and network devices. ... any docs on how to setup rules on Tripwire tool for file integrity ... As for Tripwire, that very much depends on your environment. ...
    (Focus-IDS)
  • Re: Setting up Arcsight/Tripwire
    ... You can plug literally everything into ArcSight, ... database and network devices. ... We have to setup the rules and commission Arcsight ...  If you're just now deploying, ...
    (Focus-IDS)
  • RE: Setting up Arcsight/Tripwire
    ... I concur with getting help and training configuring Arcsight ... database and network devices. ... if you have any docs on how to setup rules ...
    (Focus-IDS)
  • Re: Setting up Arcsight/Tripwire
    ... be instantly deployed & added to Arcsight ESM for monitoring Windows, ... UNIX, database and network devices. ... and correlations. ... I'm also not sure why the overposter is catching such flak for asking about community rules. ...
    (Focus-IDS)
  • Re: Setting up Arcsight/Tripwire
    ... I was wondering if anyone has any standard rules and policies which can ... be instantly deployed & added to Arcsight ESM for monitoring Windows, ... any docs on how to setup rules on Tripwire tool for file integrity ... As for Tripwire, that very much depends on your environment. ...
    (Focus-IDS)

Loading