Working with Change Auditor data within ArcSight
Table 12. Mapping information
Working with ArcSight subscriptions through the client
To create an ArcSight subscription
1
2
4
5 Click Next to select the events to forward based on subsystem and event date. Once the subscription is created the starting event date and time cannot be changed.
▪ By default, events start sending after the subscription is created. To change when to begin sending events, click Send events starting and select the desired date and time.
6 Click Finish.To view existing ArcSight subscription details:
1To edit the ArcSight subscription
1
5 Click Finish.To remove a subscription
1To enable and disable a subscription
To refresh the summary information
1
2 Click Refresh.
New-CAArcSightEventSubscription
Use this command to create the subscription required to send Change Auditor event data to ArcSight.
$allSubsystems = Get-CAEventExportSubsystems -Connection $connection
Get-CAArcSightEventSubscriptions
Use this command to see the details of the current ArcSight subscriptions.
Table 13. Available parameters
Example: List defined ArcSight subscriptions Get-CAArcSightEventSubscriptions -Connection $connection
The command returns the following information.
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center