Skip to content

InfoSec Pro

  • From the compliant log monitoring to advanced threat detection
  • About me

ESM ArcSight

Smart Connector “Filter Out” issue

8 July 2014 by alex

ArcSight Smart Connectors has a very useful feature: it is possible to set up a filter to filter out unwanted events and don’t send them to a destination (ESM ArcSight, Logger, etc). It works very well at the ESM ArcSight – you just need to open connector’s properties, select the “Filter” tab and create a … Read more

Categories ArcSight, SIEM Tags ESM ArcSight, Filter, Logger, Smart Connector Leave a comment

ESM ArcSight – how to convert events for Replay (Test Alert) agent

2 November 2012 by alex

The “Replay” (also known as Test Alert) agent at the ESM ArcSight – is a very powerful tool for developing and debugging rules. You don’t need to wait until a real (and probably rare!) event will be received by the ESM Manager only to check that the rule produced incorrect result. Of course a test … Read more

Categories SIEM Tags csvconvert, ESM ArcSight, Replay, Test Alert Leave a comment

Recent Posts

  • The untold story of the PIVX hack
  • Slow evolution of ERC-20
  • Beware of browser “miners”
  • Splunk certified Architect
  • Splunk certified

Recent Comments

  1. Naseer on Logger and CIFS share on a Windows 2008 R2 Server
  2. Ali on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
  3. alex on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
  4. Nazeer Ahmed on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
  5. flink on X11 strikes back – MIT-MAGIC-COOKIE-1 data did not match
© 2025 InfoSec Pro • Built with GeneratePress