Micro Focus ArcSight Logger is a comprehensive solution for security event log management that simplifies compliance and facilitates efficient log search. By integrating ArcSight Logger with CloudDefense.ai, you can monitor and analyze security vulnerabilities across your applications seamlessly.
Setting Up Micro Focus ArcSight Logger Integration
Obtain the API Key from CloudDefense.ai:
Log in to CloudDefense.ai and navigate to Profile Management.
Copy your API key from the Profile Management page.
Get the Vulnerability Listing REST API Endpoint:
Use the following API endpoint with the application ID at the end to retrieve the list of all vulnerabilities: https://console.clouddefenseai.com/api-v2/integrations/application/{application-id}
Replace {application-id} with the specific application ID to obtain a list of vulnerabilities for that application.
Add a header with the API key and paste your API key obtained from the Profile Management page.
Configure the FlexConnector Feature:
To configure CloudDefense's HTTP API with ArcSight Logger, use the FlexConnector feature from Micro Focus ArcSight Logger.
Create a Custom Parser:
Create a custom parser within ArcSight Logger to interpret the JSON data returned by the API.
Follow the instructions provided in the Micro Focus ArcSight Logger official documentation< https://www.microfocus.com/documentation/arcsight/arcsight-smartconnectors-8.3/pdfdoc/RESTFlexConn_DevGuideConfig/RESTFlexConn_DevGuideConfig.pdf > to create the custom parser.
Example JSON Schema
Below is an example schema that you can use to parse vulnerabilities data
Benefits
Simplified Compliance: Monitor security events and logs across your applications for easier compliance reporting.
Efficient Log Search: Quickly search for specific vulnerabilities and events within your applications.
Custom Alerts: Create customizable alerts based on severity levels, status, and other key attributes.
By following these steps, you'll successfully integrate Micro Focus ArcSight Logger with CloudDefense.ai, providing your organization with comprehensive vulnerability monitoring and efficient log management.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article