Configuration to Import HP ArcSight CEF Flat File to SailPoint
-
Access the Application Configuration Console.
-
Go to the Schema tab.
Enter the correlation key for which you want to correlate activity from HP ArcSight to SailPoint.
For example, for Active Directory application:
sAMAccountName
-
Go to the Activity Data Sources tab.
Note
For more information on Activity Data Source, refer to the IdentityIQ Administration Guide in SailPoint Product Documentation. -
Select Add to add a new Activity Data Source.
-
Set the Activity Data source type as CEF Log File. The default transformation rule and correlation rule will be automatically selected.
Note
You can change the value ofcefLinkAttribute
in the correlation rule to set correlation keys as needed in the application. -
Go to the Transport Settings tab and set the Transport Type as local, ftp or scp.
-
Go to the Log File Settings tab and in the File name, provide the exact path of the CEF flat file.
For example:
C:\ArcSight\activedirectory.csv
-
Select the Save button to save activity data source configuration.
If the correlation key is not set and the account aggregation for that application is already performed, then perform the following:
-
Access the Application Configuration console.
-
Go to the Correlation tab.
-
Select the New button to create a new Account Correlation.
-
Select the Next button and provide the name of the configuration.
-
Select the Application Attributes and Identity Attributes and select Add button.
-
Select Save.
-
Select Save to save the application.
After the correlation configuration is done, execute the account aggregation (with optimization turned off to pick up the existing accounts) again.
-
Go to Define > Identities.
-
Select the identity for which you want to enable Activity monitoring and import data from ArcSight.
-
Go to the Activity tab.
-
Enable Activity Monitoring.
-
Save the Identity.
-
Go to Monitor > Tasks.
-
Create a new Activity Aggregation Task.
-
Select an activity data source you configured earlier.
-
Save and execute the task.
-
To see the result of the task executed in previous step go to the Task Results tab and select the task.
-
To see the correlated events go to Define > Identities. Select the identity for which you have correlated the event. Go to the Activity Tab. Check the Recent Activities section.
-
Note
After correlating the HP ArcSight event to Identity, the Policy Violation and Certification can be created and used to notify for any activity for that identity using the workflow.