The L1-Host Monitoring - Indicators and Warnings package is designed to monitor and track the availability of system host and service accounts that may have certain security and/or operational significance. This package has to be integrated with any Product packages which collect and filter out these device events for hosts and host components. This package can be also be integrated with but does not require, the L2 Host Monitoring-Situational and Awareness package for further detections and investigations.
The idea to have the L1 Host Monitoring Indicators and Warnings package is to build some common functionality (such as Rules) that can be applied by multiple Product packages. The Rule filters for the L1 package will exist which reference corresponding null (False) filters in the L1 package. Wherever possible, only the filters will reside within the product packages. Those filters in the product package will then be linked into an OR statement in the null (false) L1 package filter where appropriate.
Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.
added support for MITRE ATT&CK tagging
This update includes resources to identify two new use cases:
- Device Config Configuration Change
- Essential Configuration Change
This version requires Activate Base 2.5.1
1. Update the schema type of 2 Active lists:
/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Indicators and Warnings/System Errors/Service Down with Host Name Key
/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Indicators and Warnings/System Errors/Service Down with Service Name Key
2. Added 2 new UC:
User Story 1: Multiple services down on the same host (Not worry about the services back up within time windows)
User Story 2: Multiple services extended down on the same host (any service stop and back up within time windows will not consider the service is down; Only the service is completely down during time windows is consider the service down.)
User Story 1: Same service down on the Multiple Hosts (Not worry about the service back up within time windows)
User Story 2: Same service extended down on the same host (any service stop and back up within time windows will not consider the service is down; Only the service is completely down during time windows is consider the service down.)
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox