2019-02-05 10:43 AM
Any pointers to help me with the RSA SIEM ( 11.1.x) Integration with HP ITSM Ticketing Tool . Thanks in Advance !
2019-02-09 08:29 PM
Hello Hari
1. If you are trying to collect logs from HP ITSM Ticketing Tool in a RSA NetWitness Log Collector, then unfortunately as you probably realize the HP ITSM Ticketing Tool is not a supported device type by RSA NetWitness.
Reference: RSA Supported Event Sources - https://community.rsa.com/community/products/netwitness/parser-network/event-sources
Without knowing the sort of logs that are generated by the HP ITSM Ticketing Tool it is difficult to advise you.
However you can consider creating your own RSA NetWitness device parser using the RSA NetWitness Log Parser Tool (NwLPT)
Reference: RSA, a Dell Technologies business, announces the release of RSA NetWitness Log Parser Tool v1.0 and the RSA NetWitness Log Parser Community - https://community.rsa.com/docs/DOC-85208
2. If instead you are trying to send NetWitness alert/incidents to the HP ITSM Ticketing Tool please investigate if the RSA NetWitness Alerting and Incident management output actions can be received by the HP ITSM Ticketing Tool from the NetWitness ESA or NetWitness Respond services.
References:
NetWitness Respond Configuration Guide for Version 11.x - https://community.rsa.com/docs/DOC-96840
NetWitness Respond User Guide for Version 11.2 - https://community.rsa.com/docs/DOC-96363
Alerting with ESA Correlation Rules User Guide for Version 11.x - https://community.rsa.com/docs/DOC-80068
ESA Configuration Guide for Version 11.x - https://community.rsa.com/docs/DOC-80138