Skip to content

InfoSec Pro

  • From the compliant log monitoring to advanced threat detection
  • About me

csvconvert

ESM ArcSight – how to convert events for Replay (Test Alert) agent

2 November 2012 by alex

The “Replay” (also known as Test Alert) agent at the ESM ArcSight – is a very powerful tool for developing and debugging rules. You don’t need to wait until a real (and probably rare!) event will be received by the ESM Manager only to check that the rule produced incorrect result. Of course a test … Read more

Categories SIEM Tags csvconvert, ESM ArcSight, Replay, Test Alert Leave a comment

Recent Posts

  • The untold story of the PIVX hack
  • Slow evolution of ERC-20
  • Beware of browser “miners”
  • Splunk certified Architect
  • Splunk certified

Recent Comments

  1. Naseer on Logger and CIFS share on a Windows 2008 R2 Server
  2. Ali on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
  3. alex on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
  4. Nazeer Ahmed on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
  5. flink on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
© 2025 InfoSec Pro • Built with GeneratePress