You can install ArcSight SmartConnector on Linux by using the console instead of the GUI installer.
To install ArcSight SmartConnector by using the console:
%ARCSIGHT_HOME%
).The default value of the installation directory is /root/ArcSightSmartConnectors
.
We recommend that you specify Don't create links
.
After ArcSight SmartConnector is installed, the following information will be displayed in the console:
Installation Complete
---------------------
The core components of the ArcSight SmartConnector have been successfully installed to:
%ARCSIGHT_HOME%
To finish the configuration of the SmartAgent, please go to the folder:
%ARCSIGHT_HOME%/current/bin/
and execute the script:
./runagentsetup.sh
%ARCSIGHT_HOME%/current/bin/runagentsetup.sh
.Add a Connector
.Syslog Daemon
as the connector type.Specify the port to which Feed Service sends events. This port is specified in the Connection settings section of the Service tab of Kaspersky CyberTrace Web (by default, it is 9998
).
Specify the IP address to which Feed Service sends events. This IP address is specified in the Connection settings section of the Service tab of Kaspersky CyberTrace Web (by default, it is 127.0.0.1
).
You can specify ALL
if you want Arcsight SmartConnector to receive events from all network interfaces of the computer on which it runs. (Note that you cannot specify ALL
in the Feed Service configuration file.)
Specify Raw TCP
.
Specify false
.
ArcSight Manager (encrypted)
as the destination type.It is recommended to specify yes
.
ArcSight Manager host.
ArcSight Manager port. By default, it is 8443
.
Name of the user that has the right to register a connector in ArcSight.
Password of the specified user.
Specify False
.
Specify False
.
Specify False
.
Arbitrary value can be specified.
Arbitrary value can be specified.
Arbitrary value can be specified.
Arbitrary value can be specified.
After this, the connector will be registered.
Import the certificate to connector from destination
.If correct data is displayed, type yes
.
Install as a service
.Indicates whether the service will start on the system startup. We recommend that you specify yes
.
The connector will be installed as a service.
/etc/init.d/arc_$service_name start
In this command, $service_name
is the service internal name that you specified.
After you have installed ArcSight SmartConnector, you can install Feed Service and integrate it with ArcSight. For more information, see section "Integration steps (ArcSight)".
Page top