This is a simple demo video of the way that you create and run a correlation rule with ArcSight ESM. Please note the correlation rule is a simple one and what is often known as an “aggregation rule“. This is the simplest type, but its great to show for a demo about how its all drop downs and clicks, rather than searching, writing Regex or anything like that.
1 view
4309
1541
4 years ago 00:07:17 1
HPE ArcSight ESM Simple rule creation
4 years ago 01:07:20 2
Мониторинг событий ИБ на базе решений HP ArcSight ESM и HP ArcSight Logger