Make sure that Kaspersky CyberTrace Service listens on the port to which Forwarding Connector sends data from ArcSight ESM.
Make sure that Kaspersky CyberTrace Service sends the events to ArcSight SmartConnector.
Check that ArcSight SmartConnector is configured properly.
For this purpose, run the following command:
%ARCSIGHT_HOME%/current/bin/runagentsetup.sh (in Linux)
%ARCSIGHT_HOME%\current\bin\runagentsetup.bat (in Windows)
Here, %ARCSIGHT_HOME% is the directory where ArcSight SmartConnector is installed.
Problem: An active channel does not display events after a new ARB package is imported
To solve this problem, try the following actions:
Check the filter used in the active channel:
Go to Filters → Shared → All Filters → Public → Kaspersky CyberTrace Connector.
Make sure that the device product field has the value of Kaspersky CyberTrace for ArcSight.
Create a new active channel:
Delete the current active channel, and then create a new one.
Configure the new active channel as follows:
Set the Start Time and End Time parameters as you wish.
Set the Use as Timestamp parameter to Manager Receipt Time.
If you want the active channel to be updated automatically, select Continuously evaluate in the Time Parameters section of the active channel's properties.
In the Filters section, specify the filter that has the same name as the active channel itself. You can find available filters in the tree view of ArcSight Console, at the Filters → Shared → All Filters → Public → Kaspersky CyberTrace Connector location when the Filters item is selected in the drop-down box.
In the Fields section, specify the item that has the same name as the active channel itself.
You can find available fields in the tree view of ArcSight Console, at the Field Sets → Shared → All Field Sets → Public → Kaspersky CyberTrace Connector location when the Field Sets item is selected in the drop-down box.
Problem: Kaspersky CyberTrace Service does not receive events from ArcSight
Make sure that the ArcSight forwarding connector that you installed is running.
In Linux, you can use the following command for this purpose:
ps -Af | grep %DIR_NAME%/current/bin
Here, %DIR_NAME% is the directory in which the forwarding connector is installed. If the forwarding connector process is running, the information about it will be displayed in the console.
If Kaspersky CyberTrace Service stopped receiving events from ArcSight after a new ARB package is imported, register ArcSight Forwarding Connector once more by running the following command, and then following the instructions of the wizard: