Personal blog of Alex Muratov

Snorby & Snort is up and running Finally I setup my home IDS: Snort & Snorby on top. The goal: to see what is going on in my Internet traffic, is there anything interesting. Also Snort output …Continue reading →

Smart Connector “Filter Out” issue TAGS: | | | ArcSight Smart Connectors has a very useful feature: it is possible to set up a filter to filter out unwanted events and don’t send them to a destination (ESM ArcSight, …Continue reading →

Default utility Image

ESM ArcSight plugin – correct device time TAGS: | | | Recently I find out a situation when some device puts time stamps using the GMT time zone. It could be easily fixed by changing connector settings. But here is a …Continue reading →

ESM ArcSight plugins – how to TAGS: | | | Introduction I attended many sessions at the “HP Protect 2012” conference last September and one of them – the “Plug it in!” by Doron Keller (HP/ArcSight) was very interesting for …Continue reading →

ESM ArcSight – how to convert events for Replay (Test Alert) agent TAGS: | | | The “Replay” (also known as Test Alert) agent at the ESM ArcSight – is a very powerful tool for developing and debugging rules. You don’t need to wait until a …Continue reading →

Log management and threat detection TAGS: | I wrote a small introduction article about log monitoring and how it relates to advanced threats detection. Why using of SIEM is important. Read the article.

BOINC

BOINC

Ads

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Calendar

September 2017
M T W T F S S
« Aug    
 123
45678910
11121314151617
18192021222324
252627282930  
%d bloggers like this: