For ArcSight ESM to receive events from Kaspersky Scan Engine, an ArcSight SmartConnector of the Syslog Daemon type must be installed. You can install ArcSight SmartConnector on any computer that can connect to Kaspersky Scan Engine and to ArcSight ESM.
To install an ArcSight SmartConnector:
This application is a component of HP ArcSight and is not included in Kaspersky Scan Engine.
%ARCSIGHT_HOME%
).Selecting Add a Connector
If this window is not displayed, run the following command:
%ARCSIGHT_HOME%/current/bin/runagentsetup.sh
You specify the same port in the Kaspersky Scan Engine Syslog settings.
You specify the same IP address in the Kaspersky Scan Engine Syslog settings.
You can specify (ALL) if you want Arcsight SmartConnector to receive events from all network interfaces of the computer on which it runs. Note that you cannot specify (ALL) in the Kaspersky Scan Engine configuration file.
Defining connector parameters
Click Next.
Selecting the type of destination
Click Next.
Defining destination parameters
Click Next.
Click Next.
If you do not run the installation as root, the following warning is displayed:
If you do not run the installation as root
The %ARCSIGHT_HOME%/current/logs/agent.log
file contains messages about the installation process.
You can skip the next step that describes how to specify the service parameters.
If you run the installation as root, select Install as a service.
Click Next.
We recommend that you set the service name, specified in Service Internal Name, to be the same as the connector name.
Defining service parameters
Click Next.
/etc/init.d/arc_$service_name start
In this command, $service_name
is the service internal name.
After the ArcSight ESM configuration is complete, you can configure Kaspersky Scan Engine.
Page top