Академический Документы
Профессиональный Документы
Культура Документы
Agenda
Overview
Application health
Events in
Events out
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Data to information
ESM 101: Concepts for ESM + CORR-Engine provides a full overview of event flow.
Connectors
Smart
Connectors
collect &
normalize
events form
environment
Network model
Details
regarding
networks,
assets, zones
etc.
Use case
Customizing
rules, data
monitors, lists, to
fit your business
needs
Report
Dashboards
Traditional
reports
ArcSight Solution
Packages
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Hierarchy
Scale with
additional
Appliances to
accomodatee
volume and
reporting needs
Management Console
Manage Users accounts, storage, connectors, notifications and license
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Dashboards
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
10
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
12
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
MySQL seamlessly handles the joins (e.g.: events and cases, actors)
Patent-pending technology superstore (single database with Row and Column
store)
13
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
CORR-Engine: Overview
CORR-Engine
C
o
C
O
E m
n m
g
ESM
R
i L
Manager
R
-
n a
e y
e
r
14
Events
Logger
Event
ArcSight
Event
Store
Server
Store
Events
MySQL
Resources
and data
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Logger
Storage
Engine
InnoDB
Storage
Engine
15
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
16
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
18
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
19
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Manager logs
Manager logs
Manager logs
Thread dumps
Database logs
System tables
DB sessions
Manage.Jsp
Database logs
20
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
21
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
22
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
23
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Event retention
Max event storage size: 919GB
MRT(manager-receipt-time) based data retention(not end time)
Oldest events will be overwrite first(FIFO)
Events pruning based on the age of events
25
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
26
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Storage layout
Event storage layout
1-Jul
2-Jul
3-Jul
4-Jul
5-Jul
6-Jul
27
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Archives
Data files containing events of one day, which have been copied to the archive location, with two
additional files containing metadata related to these data files.
28
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Event flow
29
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Archiving process
A subdirectory with the format YYYYMMDD is created for each day to store the archive. If the directory is
already present, then it is removed first.
Two metadata files, an XML and CSV, for the archival information are created
These files are compressed and copied to the archiving location.
Finally, the data files containing the events are copied to the archive location.
Note : The archiving is continual and is copying the events files offline as opposed
to what used to be in ESM where the same partition was taken offline. Does not
affect events in online retention
30
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Archiving modes
There are two modes of archiving:
Scheduled - Runs on a daily basis, archiving the events from the day before.
Manual (user-driven)
We recommend to use scheduled mode and use the manual mode for retrying an
unsuccessful scheduled one.
31
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
32
Changing the size and the location of the archive folder is is not supported in AE 3.0
If there is no more space the archiving will fail.
We can monitor the space used in the management-ui
Mounting external drive to the archive directory is not supported.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
33
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
34
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Archive jobs
35
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
36
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Archives
37
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
38
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
archive:100
Archive created
archive:101
Archive deleted
archive:102
archive:103
archive:110
Archive activated
archive:111
archive:112
archive:120
archive:121
archive:122
archive:130
Archive deactivated
archive:131
archive:132
archive:140
Archive scheduled
archive:141
archive:142
39
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
40
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Service:EventArchiveManager
Look for Service:EventArchiveManager in the server.status.log
[2011-10-03 03:55:22,456] Service:EventArchiveManager
[2011-10-03 03:55:22,456] ObjectName:Arcsight:service=EventArchiveManager
[2011-10-03 03:55:22,539]
ArchiveEnabled="true"
[2011-10-03 03:55:22,623]
[2011-10-03 03:55:22,623]
ConfiguredDaysInRetentionPolicy="0"
[2011-10-03 03:55:22,666]
DiskspaceFree="210453397504"
[2011-10-03 03:55:22,708]
LocationOnDisk="/opt/arcsight/logger/data/archives"
[2011-10-03 03:55:23,559]
OfflineArchives="[
41
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
42
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
In case of File System inconsistency the system prompts to run fsck (file system check) to fix it.
44
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Diagnosing tools
Commands to validate hardware failure:
HP Appliances (RAID Controller and disks)
ipmitool sel
ipmitool sensor
dmesg
cat /var/log/messages
45
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
46
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
47
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Types of RMA
Four key scenarios of RMA:
Single Failed Hard Drive replace drive
Multiple Failed Hard Drives replace entire appliance
Failed PSU (one or more) replace PSU
Internal hardware failure (CPU, RAM, M/B, RAID controller, etc) replace entire appliance
48
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Filing an RMA
To avoid delays, be sure to provide all information below:
Contact Full Name
Company Name
Address (no PO boxes)
City, State, Postal Code
Country (if outside of US, must include)
Contact Phone Number:
VAT/Tax ID# (if outside of US, must include)
Serial Number of Defective Appliance:
Model:
ArcSight Version:
Technical Reason:
49
Work with ArcSight Support to review all data and file RMA with the above information.
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Your feedback is important to us. Please take a few minutes to complete the session survey.
50
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Thank you
Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.