Step 2 (alternative). Installing ArcSight Forwarding Connector by using the console
April 11, 2024
ID 167566
You can install ArcSight Forwarding Connector by using the console instead of the GUI installer.
To install ArcSight Forwarding Connector by using the console:
- In the console, run the ArcSight Forwarding Connector installer.
- Read the Introduction section and press Enter.
- When prompted, select Choose Install Folder, and type the full path to the directory where ArcSight Forwarding Connector will be installed (
%ConnectorInstallDir%
).The default value of the installation directory is
/root/ArcSightSmartConnectors
- When prompted, select Choose Install Set, and type
1
(stands forTypical
). - When prompted, select Choose Link Location, and specify whether a link to the installation directory must be created.
We recommend that you specify
Don't create links
. - Make sure that the Pre-Installation Summary section lists the correct values of the installation settings. Press Enter if the values are correct.
After ArcSight Forwarding Connector is installed, the following information will be displayed in the console:
Installation Complete
---------------------
The core components of the ArcSight SmartConnector have been successfully installed to:
%ConnectorInstallDir%
To finish the configuration of the SmartAgent, please go to the folder:
%ConnectorInstallDir%/current/bin/
and execute the script:
./runagentsetup.sh
- Run
%ConnectorInstallDir%/current/bin/runagentsetup.sh
. - At the prompt, select
Add a Connector
. - Specify
ArcSight Forwarding Connector
as the connector type. - Specify whether to mask passwords.
We recommend that you specify
yes
. - Specify the following connection parameters of ArcSight Source Manager:
- Host Name
ArcSight Source Manager host.
- Port
ArcSight Source Manager port (by default, it is
8443
). - User
User name of the account intended for use by ArcSight Forwarding Connector (by default, it is
FwdCyberTrace
).You can also specify a user other than
FwdCyberTrace
. To do so, specify a custom ArcSight user in the ArcSight Forwarding Connector settings. - Password
Password for the account intended for use by ArcSight Forwarding Connector (by default, it is
KasperskyLab!
).
- Host Name
- Specify the following action for importing the certificate:
Import the certificate to connector from destination
. - Specify the destination type:
CEF Syslog
. - Specify the following settings:
- Ip/Host
IP address that Kaspersky CyberTrace Service listens on for events.
- Port
Port through which Kaspersky CyberTrace Service receives events. By default, it is
9999
. - Protocol
Specify
Raw TCP
.
The IP address and port are the same as specified in the Connection settings section of the Service tab of Kaspersky CyberTrace Web.
- Ip/Host
- Specify the following connector settings:
- Name
Arbitrary value can be specified.
- Location
Arbitrary value can be specified.
- DeviceLocation
Arbitrary value can be specified.
- Comment
Arbitrary value can be specified.
After this, the connector will be registered.
- Name
- Specify the way in which the connector must be installed:
Install as a service
. - Specify the service settings:
- Service Internal Name
- Service Display Name
- Start the service automatically
Indicates whether the service will start on the system startup. We recommend that you specify
yes
.
- Check the specified data. If it is correct, press Enter.
The connector will be installed as a service.
- Make sure that the connector is running (see the section about ArcSight troubleshooting on how you can do this). If it is not running, start it by using the following command:
/etc/init.d/arc_%FORWARDING% start
Here
%FORWARDING%
is the name of the connector.
If the forwarding connector sends a large amount of events (more than 1000 events per second) to Kaspersky CyberTrace Service, we recommend that you do the following: in the %ConnectorInstallDir%/current/user/agentagent.wrapper.conf
file, set the wrapper.java.maxmemory
field to 512
and restart the forwarding connector.