Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
1354 Views 4 Replies Latest reply: Feb 22, 2013 4:24 PM by infosecjeff RSS
infosecjeff Newcomer 44 posts since
Sep 11, 2010
Currently Being Moderated

Feb 22, 2013 10:43 AM

Web Gateway 7.2 and HP ArcSight access logs

Has anyone had the pleasure of configuring the log handler for ArcSight?  I'm looking for some guidance on how they need the access logs delimited.

  • btlyric Apprentice 184 posts since
    Aug 1, 2012
    Currently Being Moderated
    1. Feb 22, 2013 12:23 PM (in response to infosecjeff)
    Re: Web Gateway 7.2 and HP ArcSight access logs

    You have three choices.

     

    There is an ArcSight SmartConnector for MWG. Theoretically, that would handle the default access.log format that ships with the product.

     

    You could send whatever to ArcSight and then use a script on your logging collector to manipulate the data into CEF format.

     

    You could build your CEF line in the MWG log handler.

     

    If you google for arcsight common event format that will bring back a bunch of links, including the ArcSight guide to CEF and how to format log lines.

  • cnewman McAfee SME 40 posts since
    Jan 31, 2011
    Currently Being Moderated
    2. Feb 22, 2013 1:22 PM (in response to btlyric)
    Re: Web Gateway 7.2 and HP ArcSight access logs

    That is 100% correct. But I can help a bit more.

     

    The smart connector was created for MWG 6, and last I saw on the arcsight site they hadn't updated the instructions. You could easily make MWG7 produce that format. If you want to use the connector and punch the raw logs over, that is the way to go.

     

    However, if you want to do syslog and get realtime data, you need to go CEF and syslog.

    Buyer beware, I would test on a non production setup first, and keep in mind this is extremely chatty. If you generate 500 req/s, that's 500 events/s.

     

    I have a CEF format previously, see link with instructions. You can modify to taste, depending on the arcsight admin I have seen directionality become a discussion point.

     

    CEF Syslog

     

    Regards,

     

    --CN

  • Jon Scholten McAfee SME 853 posts since
    Nov 3, 2009
    Currently Being Moderated
    3. Feb 22, 2013 2:15 PM (in response to btlyric)
    Re: Web Gateway 7.2 and HP ArcSight access logs

    Hi All,

     

    Do not use the arcsight connector!

     

    It messes with the MWG's ability to rotate and delete its logs!

     

    Syslog is the cleanest, easiest, and most supported route to go.

     

    Best,

    Jon

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points