The 'NetWitness-ArcSight_Integrations' Zipped archive will contain documentation, required references and import files to create integrations between ArcSight ESM and NetWitness. It is broken down into three main integrations:
- Right-Click lookup functionality from ArcSight allowing an analyst to pivot to NetWitness and perform an investigation using one of the following queries:
- Filename
- SessionID
- Source Address (IP)
- Destination Address (IP)
- Source Address (IP) and Destination Address (IP) Combination
- Source Address (IP) and Destination Hostname Combination
- Source Address (IP) and Destination TCP/UDP Port Combination
- ESA Alert originating event callback (using Decoder ID, RID & SessionID)
- A Custom CEF Formatted ESA Notification Template and associated Global Notification Configuration to stream alert information to an ArcSight Syslog SmartConnector. This template will use the following mapping table:
- A Reporting Engine Alert CEF Syslog Template
NetWitness-ArcSight_Integrations.zip