FireEye’s detection of a malicious event generates alert details that can be sent from the appliance to an email, HTTP, SNMP, or Syslog server or Security Information and Event Management (SIEM) platform in multiple formats, including Common Event Format (CEF). MF ArcSight gathers event notifications in CEF from FireEye CMS Series appliances and other devices, network appliances, and applications. With all the information available in one place, security professionals can reduce the time to detect and resolve problems.
This guide provides information for configuring the FireEye integration for ArcSight ESM. This integration is supported on ESM versions [6.0.0.1333] and later. FireEye version(s) 8.2.0 is supported.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox