This topic shows how to create active channels manually, from triggered rules, and from filters.
Tip: Press Enter to register edits made in editors and channel columns.
To ensure that ESM registers a change you make to a field in editor and channel columns, press Enter before clicking Apply or OK.
Where: Navigator > Resources > Active Channels
To create or edit an active channel:
Locate an active channel group.
If you are creating an active channel, select New Active Channel.
If you are editing an active channel, expand the group, right-click an active channel, and choose Edit Active Channel.
Attribute |
Usage |
---|---|
Start Time |
The relative or absolute time reference that begins the period to track events in the channel. Edit the time expression, choose a common expression from the drop-down menu, or click the Selector button to choose an absolute date and time value. See Timestamp Variables for more options. Notes:
|
End Time |
The relative or absolute time that ends the period to actively track the events in the channel. Edit the time expression, choose a common expression from the drop-down menu, or click the Selector button to choose an absolute date/time value. See Timestamp Variables for more options. Notes:
|
Use as Timestamp |
Choose the event-timing phase that best supports your analysis. End Time represents the time the event ended, as reported by the device. Manager Receipt Time is the event's recorded arrival time at the ArcSight Manager. |
Evaluation of time parameters |
Choose whether the channel will Continuously evaluate to show events that are qualified by Start and End times which are re-evaluated constantly while the channel is running, or Evaluate once at attach time to show only the events that qualify when the channel is first run. A channel set to |
Filter |
If creating a new channel, select an existing filter for the events processed through the channel. If you prefer, click Define to create a new filter to be used by this channel. Follow the instructions in If editing a channel, go to the Filter tab to make your edits. |
Fields |
Choose an existing event field set for the events processed through the channel. The default field set is for users who view a channel for the first time. If no default is specified, the ArcSight system default is used. When a user closes a channel, ArcSight saves the field set (and all other Console settings) to the user’s After a user has opened a channel once, the Console does not use the default field set for that user again. Changing the default only affects other users who have never opened the channel before. |
Click the Examples button to see how to specify commonly used channel values.
Entering data in the Common and Assign sections is optional, depending on how your environment is configured. For information about the Common and Assign attributes sections, as well as the read-only attribute fields in Parent Groups and Creation Information, see Common Resource Attribute Fields.
Click the Filter tab to edit the channel's filter condition as described in Creating or Editing a Filter.
To view the full conditions for the MatchesFilter operator, click the Summary tab and then click the Expand Filter button to display the filter conditions for debugging.
Note that in this case, the display of the MatchesFilter full logic does not display the sub-filter of the matched filter. Full logic is displayed only for the first level of matched filter conditions.
Click the Sort Fields tab to explicitly set which fields to sort the channel on in grid views, the sort order for those fields, and whether sorting for each field is ascending (A to Z) or descending (Z to A).
Click the Local Variables tab to use ArcSight local variables with the channel's filters.
Tip: You can create local variables, which are only available to the resource you are creating (in this case, an active channel), or use global variables. For information on creating global variables, see Creating or Editing a Filter and Global Variables.
Optional: To add information in the Notes tab, refer to Using Notes.
Click OK to save the channel and to open and run it in the Viewer panel.
To view results of triggered rules in channels:
See Verifying Rules with Events.
To create active channels from filters:
In the Filters resource tree, right-click a filter and select Create Channel with Filter.
Do the same for:
Connectors
Assets, including vulnerabilities, zones, and categories
Stages
Cases with events. For such cases, right-click and select Case Details Channel. See Viewing a Case's Events in a Channel.