Click here for official OpenText CyberRes training courses
Course: TITAN-ARC-006
ArcSight: FlexConnector Development
Virtual Instructor Led / Self-Paced Training
Difficulty Rating
Course Duration: 1 Day
The participants will obtain certificates signed by Titan Labs (course completion).
Course Description
This course teaches you the essentials of ArcSight FlexConnector development, taking everything covered in the Troubleshooting Unparsed Events course and amplifying it!
Building on our TITAN-ARC-004: Troubleshooting Unparsed Events course, which offered a lightweight introduction to FlexConnectors, this course takes a deep dive into the nitty gritty of FlexConnectors. Students will gain an in-depth understanding of the architecture and components of the FlexConnector, including a host of advanced operations.
Students will also get hands-on creating their own FlexConnectors, and be trained up on using the ArcSight FlexConnector & Regex Tools.
Modules
Overview of ArcSight SmartConnectors
Understanding the SmartConnector Framework
Where SmartConnectors sit in the ArcSight Architecture
Introduction to FlexConnectors
Different types of FlexConnector and when to use which
The differences between SmartConnectors and FlexConnectors
Installing your first FlexConnector
Pre-requisites to installation
Installing the connector
ArcSight Schema
What is it and why is it so important
Schema Groups
Components of a FlexConnector
What are the components of a FlexConnector
How to create each component
When would you need each component
FlexConnector Development Tools
FlexAgent Wizard for simple setups
ArcSight Regex Tool
Deep Dive into FlexConnector Parsers
Regex Parsers
Database parsers
Time-based parsers
SNMP parsers
And more…
Advance FlexConnector Operations
Multi-Line Parsing
Conditional Mappings
Extra Processors
Guide to writing regex
Intended Audience
This course is designed for Security Professionals and SOC Administrators, who are responsible for deploying and administrating the ArcSight product suite within their environment.
Recommended Skills
Familiarity working with command line tools
Experience deploying applications in Windows and Linux environments
Completion of the ArcSight: Training & Development Bundle