Installation of Smart Connector(s)
The basic integration with EclecticIQ Platform consists of an ArcSight Smart Connector and the provided EclecticIQ base content package for ArcSight ESM.
The recommended connector to be used is a syslog daemon connector to receive threat intelligence in CEF format and send it into ArcSight ESM.
This connector can be installed on a separate connector server.
For a bi-directional integration, a second ArcSight CounterACT Smart Connector is needed to talk back to EclecticIQ Platform to create sightings in the EclecticIQ Platform.
Prerequisites
A running ArcSight ESM instance.
A running EclecticIQ Platform instance.
A separate connector server to install the receiving syslog daemon connector.
Open a TCP or UDP port to that server for the syslog daemon connector, TCP 1514.
Install the smart connectors
Log in to EclecticIQ Platform via SSH.
Create a user named arcsight and a directory to host the connectors and set its permissions:
sudo useradd arcsightsudo passwd arcsightsudo mkdir-p/opt/arcsight/connectorssudo chown –Rv arcsight:arcsight/opt/arcsight/Upload the latest 64 bit ArcSight Connector binary to the platform.
Install the receiving syslog daemon connector as user arcsight:
sh ArcSight-7.3.0.7886.0-Connector-Linux64.bininstall the connector in /opt/arcsight/connectors/eiq-cef-syslog-daemon.
Run the connector configuration as user arcsight:
/opt/arcsight/connectors/eiq-cef-syslog-daemon/current/bin/runagentsetup.shUse the following settings:
Type: Syslog DaemonNetwork Port:1514IP Address: (ALL)Protocol: Raw TCPForwarder: falseArcSight Manager Destination:Manager Hostname: <ESM fully qualified domain name>Manager Port:8443User: <user allowed to register connectors>Password:********AUP Master Destination: trueFilterOutAllEvents: falseEnable Demo CA: falseConnector detailsName[]:eiq-cef-syslog-daemonLocation[]: eiq-platform.localDeviceLocation[]:Comment[]: TCP syslog connector-port1514forCEFinputInstall the connector service wrapper script as root:
sudo/opt/arcsight/connectors/eiq-cef-syslog-daemon/current/bin/arcsightagentsvc-i-u arcsight-sn eiq-cef-syslog-daemonStart the connector service:
sudo/etc/init.d/arc_eiq-cef-syslog-daemon startMake sure the connector is running and listens on the configured port:
sudo netstat –tlpn |grep1514The receiving connector should appear in a running state in the ArcSight Console:
Connectors/Shared/All Connectors/eiq-arc.local/eiq-syslog-cef_tcp(running).
The connector logs its operations to:
/opt/arcsight//opt/arcsight/connectors/eiq-cef-syslog-daemon/current/logs