Description

The L1-Host Monitoring - Indicators and Warnings package is designed to monitor and track the availability of system host and service accounts that may have certain security and/or operational significance. This package has to be integrated with any Product packages which collect and filter out these device events for hosts and host components. This package can be also be integrated with but does not require, the L2 Host Monitoring-Situational and Awareness package for further detections and investigations.

The idea to have the L1 Host Monitoring Indicators and Warnings package is to build some common functionality (such as Rules) that can be applied by multiple Product packages. The Rule filters for the L1 package will exist which reference corresponding null (False) filters in the L1 package. Wherever possible, only the filters will reside within the product packages. Those filters in the product package will then be linked into an OR statement in the null (false) L1 package filter where appropriate.

Minimum Requirements

Suggested apps

Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.

Releases

Release
Size
Date
L1-Host Monitoring 1.3.0.0
34.8 KB
  |  
Nov 12, 2019
More info Less info
Product compatibility
Version 7.0 · 7.2
Version 6.11
Release notes

added support for MITRE ATT&CK tagging

Languages
English
L1-Host Monitoring 1.2.1.0
30.7 KB
  |  
Jan 19, 2018
More info Less info
Product compatibility
Version 6.8 · 6.11.0 · 6.9.1
Release notes

This update includes resources to identify two new use cases:

- Device Config Configuration Change

- Essential Configuration Change

Languages
English
L1-Host Monitoring 1.2.0.0
26.7 KB
  |  
Mar 31, 2017
More info Less info
Product compatibility
Version 6.8 · 6.11.0
Version 7.0 · 7.2 · 7.3 · 7.4 · 7.5 · 7.6 · 7.7 · 7.8
Release notes

This version requires Activate Base 2.5.1

1. Update the schema type of 2 Active lists:

/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Indicators and Warnings/System Errors/Service Down with Host Name Key

/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Indicators and Warnings/System Errors/Service Down with Service Name Key

2. Added 2 new UC:

  • Use Case: Detect Multiple Services Down on Same Host

User Story 1: Multiple services down on the same host (Not worry about the services back up within time windows)

User Story 2: Multiple services extended down on the same host (any service stop and back up within time windows will not consider the service is down; Only the service is completely down during time windows is consider the service down.)

  • Use Case: Detect Same Service Down on Multiple Hosts

User Story 1: Same service down on the Multiple Hosts (Not worry about the service back up within time windows)

User Story 2: Same service extended down on the same host (any service stop and back up within time windows will not consider the service is down; Only the service is completely down during time windows is consider the service down.)


Languages
English
L1-Host Monitoring 1.1.0.0
17.8 KB
  |  
Nov 7, 2016
More info Less info
Product compatibility
Version 6.8 · 6.11.0
Version 7.0 · 7.2 · 7.3 · 7.4 · 7.5 · 7.6 · 7.7 · 7.8
Release notes
  • Removed Type!=Correlation from the rule condition to make it running more efficiently
  • Recreated the Active List and Customizations packages to meet a standard format
  • Updated the installation script to match the current L1 package version 
Languages
English

Resources

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2024-12-3-sha256-6304 | Sun Dec 15 20:16:44 PST 2024