
Technical white paper
11
We can also forward events from specific devices or device groups. In our example in Figure 10, we have created a
forwarder based on a device group named CSE and a forwarder named CSE Application Events. All events from systems that
are part of the device group CSE will be forwarded to the HP ArcSight ESM.
Figure 10. Event Forwarding based on a Device Group
Below in Figure 11, you can see the two forwarders that were created: CSE Application Events and Windows Logon Failures.
Figure 11. Event Forwarders
Protecting HP CloudSystem Enterprise components with HP ArcSight
Configuring HP ArcSight to protect HP CloudSystem Enterprise core components involves configuring these component
applications to send security information and events from each application to the HP ArcSight ESM or HP ArcSight Logger. In
this section we will explain how to configure each CloudSystem Enterprise core component. This includes collecting
information from the operating system and application log files. This information can be collected using standard syslog
and event log collection or through the use of HP ArcSight Connectors for more detailed application and operating system
specific event logging.
To collect operating system events we will leverage the HP ArcSight Connectors. The HP ArcSight Connectors will be
installed on each host running the HP CloudSystem Enterprise applications. These applications include:
• CloudSystem Matrix Central Management Server
• Cloud Service Automation
• Operations Orchestration
• Cloud Service Automation Database server
• SiteScope
• Universal Configuration Management Database Server (UCMDB)
Cloud Service Automation and Operations Orchestration are hosted on the same Microsoft Windows® Server 2008 R2
server.
Operating system event logs are directed to the HP ArcSight logger through HP ArcSight Connectors that are specific for
each host operating system.
Commentaires sur ces manuels