ArcSight-FlexConnector-7.6- ArcSight FlexConnector Configuration -L3xx-Digital

Training Overview

This Digital Learning provides you with an overview of the ArcSight SmartConnectors framework & explains the ArcSight ESM Schema. It teaches you how to construct & manipulate FlexConnector configuration & property files & use various parsing methods, including fixed delimited, regular expressions, Syslog, & JSON. Examples from standard connectors are used to illustrate device-specific methodologies. Advanced configuration options such as multi-line Regex, parser linking, & conditional mapping are also covered.

Prerequisites

  • ArcSight ESM Administrator & Analyst training 
  • ArcSight ESM Advanced Administrator training 
  • Working knowledge of Regular Expressions

Audience Profile

This training is intended for security administrators, content engineers/architects, & IT integrators, who build & install custom connectors to provide critical event data feeds to ArcSight products.

Learning Objectives

On completion of this training, professionals should be able to: 

• Install ArcSight Connector software, configure a functional FlexConnector, & test with an ESM Active Channel 

• Use the FlexConnector Wizard to create fixed delimited configuration files 

• Use the Regex Tester tool to create common & sub-message parsing & token-to-event mapping 

• Create a tailored Categorization file for a parent FlexConnector & test its function in an active channel 

• Navigate the connector configuration file hierarchy to locate, display & edit

Content Outline

• Define SmartConnectors & their functions 

• Follow device deployment & the event flow processing 

• Describe FlexConnectors types 

• Install a Connector 

• Gather event requirements prior to developing your FlexConnector 

• Normalize & map events • Differentiate special cases 

• List the different schema groups 

• Locate FlexConnector files 

• Define the configuration procedure 

• Apply the four steps to create a FlexConnector configuration file o Parser configuration o Token declaration o Event mapping o Severity mapping 

• Use the FlexConnector wizard to install a configuration file 

• Utilize Categorization to profile an event o Six criteria are used: Object, Behavior, Outcome, Technique, Device Group, & Significance 

• Install the Regex File Reader FlexConnector 

• Create common Regex 

• Define SubMessages 

• Use the Regex Tester 

• Identify the syslog Connectors • Describe the syslog FlexConnector components 

• Create the syslog FlexConnector configuration file 

• Identify the properties of basic JSON objects 

• Define Token & Mappings declarations for a JSON Folder Follower FlexConnector 

• Perform installation & testing of a JSON Folder Follower FlexConnector in console mode

FAQs

A: To attend the training session, you should have operational Desktops or Laptops with the required specification, along with a good internet connection to access the labs. 

A: We would always recommend you attend the live session to practice & clarify the doubts instantly & get more value from your investment. However, if, due to some contingency, you have to skip the class, Radiant Techlearning will help you with the recorded session of that particular day. However, those recorded sessions are not meant only for personal consumption & NOT for distribution or any commercial use.

A: Radiant Techlearning has a data center containing a Virtual Training environment for the purpose of professional hand-on-practice. 

Professionals can easily access these labs over Cloud with the help of a remote desktop connection. 

Radiant virtual labs provide you the flexibility to learn from anywhere in the world & in any time zone. 

A: The professionals will be enthralled as we engage them the real-world & industry Oriented projects during the training program. These projects will improve your skills & knowledge & you will gain a better experience. These real-time projects will help you a lot in your future tasks & assignments.

Send a Message.


  • Enroll