Archer Integration

Administrators can integrate NetWitness with Archer Cyber Incident & Breach Response to send alerts and incidents from NetWitness to Archer for incident management and remediation. This guide provides a high-level workflow for configuring this integration.

Note: When you upgrade from Security Analytics 10.6.5 to NetWitness 11.x, the Archer Cyber Incident & Breach Response integration is no valid, and must be re-configured.

The following table list the NetWitness 11.x integration options with Archer Cyber Incident & Breach Response Version 1.3.1.2.

Archer Cyber Incident & Breach ResponseVersion NetWitness 11.x Integration Reference
1.3.1.2 ESA Correlation

See "Configure ESA Correlation for Integration with Archer Cyber Incident & Breach Response" section.

1.3.1.2 Reporting Engine (RE) See "Configure Reporting Engine for Integration with Archer Cyber Incident & Breach Response" section.
1.3.1.2 Respond

See "Configure Respond for Integration with Archer Cyber Incident & Breach Response 1.3.1.2" section.

1.3.1.2 Archer Feeds See "Archer Feeds" section.