ASFC160 - ArcSight FlexConnector Configuration
ArcSight FlexConnector Configuration provides you with an overview of the ArcSight SmartConnectors framework and explains the ArcSight ESM Schema. It teaches you how to construct and manipulate FlexConnector configuration and property files and use various parsing methods including fixed delimited, regular expressions, syslog, and JSON. Examples from standard connectors are used to illustrate device-specific methodologies. Advanced configuration options such as multi-line Regex, parser linking and conditional mapping are also covered.
Kursinhalt- Module 1: Introduction to FlexConnector
- Module 2: Using the ArcSight Schema
- Module 3: Basic and Configuration File and Categorization
- Module 4: Re…
Es wurden noch keine FAQ hinterlegt. Falls Sie Fragen haben oder Unterstützung benötigen, kontaktieren Sie unseren Kundenservice. Wir helfen gerne weiter!
ArcSight FlexConnector Configuration provides you with an overview of the ArcSight SmartConnectors framework and explains the ArcSight ESM Schema. It teaches you how to construct and manipulate FlexConnector configuration and property files and use various parsing methods including fixed delimited, regular expressions, syslog, and JSON. Examples from standard connectors are used to illustrate device-specific methodologies. Advanced configuration options such as multi-line Regex, parser linking and conditional mapping are also covered.
Kursinhalt- Module 1: Introduction to FlexConnector
- Module 2: Using the ArcSight Schema
- Module 3: Basic and Configuration File and Categorization
- Module 4: Regex FlexConnectors
- Module 5: Installing ESM Syslog Connectors with Custom Parsers
- Module 6: JSON Folder Follower Connector
- Module 7: Advanced Topics
This course is intended for security administrators, content authors/architects, and IT integrators, who build and install custom connectors to provide critical event data feeds to ArcSight ESM or Logger. This can include senior analysts for networks, security systems, enterprise applicarions and darabases.
VoraussetzungenTo be successful in this course, you should have the following prerequisites or knowledge:
- Successful completion of ArcSight ESM Admin and Analyst course
- Successful copletion of ArcSight ESM Advanced Administrator course
- Working knowledge of Regular Expressions
Es wurden noch keine FAQ hinterlegt. Falls Sie Fragen haben oder Unterstützung benötigen, kontaktieren Sie unseren Kundenservice. Wir helfen gerne weiter!
