Configuring ArcSight ESM

March 5, 2024

ID 220896

For ArcSight ESM to receive events from Kaspersky Scan Engine, an ArcSight SmartConnector of the Syslog Daemon type must be installed. You can install ArcSight SmartConnector on any computer that can connect to Kaspersky Scan Engine and to ArcSight ESM.

To install an ArcSight SmartConnector:

  1. Run the ArcSight SmartConnector installation application.

    This application is a component of HP ArcSight and is not included in Kaspersky Scan Engine.

  2. Specify the ArcSight SmartConnector installation directory (hereinafter referred to as %ARCSIGHT_HOME%).
  3. Select Don't create links.
  4. After unpacking the contents of the binary file, select Add a Connector.

    "Connector Setup" window. Selected variant "Add a Connector".

    Selecting Add a Connector

    If this window is not displayed, run the following command:

    %ARCSIGHT_HOME%/current/bin/runagentsetup.sh

  5. Select Syslog Daemon as the connector type.
  6. Specify the parameters of the connector in the Enter the parameter details form as follows:
    • Network port. Specify the port to which Kaspersky Scan Engine must send detection events.

      You specify the same port in the Kaspersky Scan Engine Syslog settings.

    • IP Address. Specify the IP address to which Kaspersky Scan Engine must send detection events.

      You specify the same IP address in the Kaspersky Scan Engine Syslog settings.

      You can specify (ALL) if you want Arcsight SmartConnector to receive events from all network interfaces of the computer on which it runs. Note that you cannot specify (ALL) in the Kaspersky Scan Engine configuration file.

    • Protocol. Specify Raw TCP.
    • Forwarder. Specify false.

    "Connector Setup" window. Network port = 9998, IP Address = (ALL), Protocol = Raw TCP, Forwarder = false.

    Defining connector parameters

    Click Next.

  7. Specify ArcSight Manager (encrypted) as the type of destination.

    "Connector Setup" window. Type of destination. Selected variant "ArcSight Manager (encrypted)".

    Selecting the type of destination

    Click Next.

  8. Specify the parameters of the destination:
    • Manager Hostname. Specify the host where ArcSight Manager is running.
    • Manager Port. Specify the port where ArcSight Manager is available. The default value is 8443.
    • User. Specify the name of the ArcSight ESM user that has rights to register the connector.
    • Password. Specify the password of the ArcSight ESM user.
    • AUP Master Destination. Specify false.
    • Filter Out All Events. Specify false.
    • Enable Demo CA. Specify false.

    "Connector Setup" window. Manager Hostname = 127.0.0.1, Manager Port = 8443, User = admin, Password is hidden, AUP Master Destination = false, Filter Out All Events = false, Enable Demo CA = false.

    Defining destination parameters

    Click Next.

  9. Specify the connector details:
    • Name (you can specify an arbitrary value).
    • Location (you can specify an arbitrary value).
    • Location of the device that must send events to the connector (you can specify an arbitrary value or leave it empty).
    • Comment about the connector (you can specify an arbitrary value or leave it empty).

    Click Next.

  10. If the ArcSight Manager parameters are valid, accept importing the certificate from the destination.
  11. If the certificate is imported successfully, install the ArcSight SmartConnector service.

    If you do not run the installation as root, the following warning is displayed:

    "Connector Setup" window. Root privileges needed.

    If you do not run the installation as root

    The %ARCSIGHT_HOME%/current/logs/agent.log file contains messages about the installation process.

    You can skip the next step that describes how to specify the service parameters.

    If you run the installation as root, select Install as a service.

    Click Next.

  12. Specify the service parameters.

    We recommend that you set the service name, specified in Service Internal Name, to be the same as the connector name.

    "Connector Setup" window. Service Internal Name = smartConnector, Service Display Name = KL Smart Connector, Start the service automatically = Yes.

    Defining service parameters

    Click Next.

  13. To start ArcSight SmartConnector, run the following command:

    /etc/init.d/arc_$service_name start

    In this command, $service_name is the service internal name.

After the ArcSight ESM configuration is complete, you can configure Kaspersky Scan Engine.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.