The L2-Host Monitoring - Situational Awareness package is designed to monitor and track these correlation or internal audit events for critical system hosts or essential services on a critical host. It depends on the result of the L1_Host_Monitoring - Indicators and Warnings package, as well as combines with the information from various internal ArcSight models, including the network model, asset model, actor model, and threat intelligence model, etc.
Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.
added support for MITRE ATT&CK Tagging
L2-Host Monitoring - Situational Awareness 1.3.1.0:
Added two new use cases:
- Device Config Configuration Change on Critical Host
- Essential Configuration Change on Critical Host
This version requires Activate Base 2.5.1
Updated the schema type of 4 Active lists:
/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Situational Awareness/System Errors/Critical Host Down or Crash
/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Situational Awareness/System Errors/Critical Host Still Down
/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Situational Awareness/System Errors/Essential Service Down on Critical Host
/All Active Lists/ArcSight Activate/Solutions/Host Monitoring/Situational Awareness/System Errors/Essential Service Still Down on Critical Host
Bug fixes
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox