This section describes how to install ArcSight Forwarding Connector.
ArcSight Forwarding Connector is a component of HP ArcSight and is not included in Kaspersky CyberTrace. You can receive this application in one of the following ways:
To install ArcSight Forwarding Connector:
%ConnectorInstallDir%
).Adding a connector
Click Next.
Selecting the connector type
Click Next.
ArcSight Source Manager host.
ArcSight Source Manager port (by default, it is 8443
).
User name of the account intended for use by ArcSight Forwarding Connector (by default, it is FwdCyberTrace
).
You can also specify a user other than FwdCyberTrace
. To do so, specify a custom ArcSight user in the ArcSight Forwarding Connector settings.
Password for the account intended for use by ArcSight Forwarding Connector (by default, it is KasperskyLab!
).
ArcSight Source Manager parameters
If an authentication error occurs (user name or password is incorrect), we recommend that you verify the FwdCyberTrace
user is present in ArcSight Console. If not, create it manually.
Click Next.
Importing the certificate
Click Next.
Specifying event format
Click Next.
The IP address and port are the same as specified on the Settings > Service tab of Kaspersky CyberTrace Web. By default, 127.0.0.1:9999
is used as the IP address and port for receiving events from ArcSight.
Specifying event destination
Click Next.
Connector details
Click Next.
Warning about user privileges
You can either run the Connector Setup Wizard as root, or run the following command as root:
%ConnectorInstallDir%/current/bin/arcsight agentsvc -i -u $username -sn $service_name
Here
$username
is the name of the operating system user that will run the service.$service_name
is the service name.We recommend that you set the service name to be the same as the connector name.
Log file %ConnectorInstallDir%/current/logs/agent.log
will contain messages about the installation process.
Skip the next step, which describes how to specify the service parameters.
Choosing installation mode
Click Next.
We recommend that you set the service name to be the same as the connector name.
Specifying service parameters
Click Next.
After this, the Connector Setup Wizard informs you that the new forwarding connector is installed.
/etc/init.d/arc_%FORWARDING% start
Here %FORWARDING%
is the name of the connector.
If the forwarding connector sends a large amount of events (more than 1000 events per second) to Feed Service, we recommend that you do the following: in the %ConnectorInstallDir%/current/user/agentagent.wrapper.conf
file, set the wrapper.java.maxmemory
field to 512
and restart the forwarding connector.