Anda di halaman 1dari 8

Data sheet

HP ArcSight SmartConnector
supported products
The HP ArcSight library of out-of-the-box SmartConnectors provides source-optimized
collection for leading security commercial products. These products span the entire stack of
event-generating source types, from network and security devices to databases and enterprise
applications. SmartConnectors are the default listing in this document.

In addition to SmartConnectors developed and maintained by HP ArcSight, we test and certify


the following connector types through our Technology Alliances Program:
Common event format (CEF) Certifiedhelps ensure event information is captured properly
in the CEF
Action Certifiedallows for control of a vendors technology from within the HP ArcSight Console
Common event format are in bold below and Action are Italicized. If they have both they are
bold and Italicized.

HP ArcSight SmartConnector supported Application security


platform for installation Arxan GuardIT
CentOS Bit9 Parity
Microsoft Windows XP Professional (SP3) CA Layer 7 SecureSpan/CloudSpan
32-bit Gateway
Microsoft Windows Server 2003 R2 (SP2) McAfee Application Control (Solidcore)
32/64-bit RSA Silver Tail Systems Forensics
Microsoft Windows Server 2008
SP2 32/64-bit Clinical/Healthcare applications
Microsoft Windows Server 2008 FairWarning
R2 SP1 64-bit
Microsoft Windows Server 2012 Cloud
Standard 64-bit Box
Red Hat Enterprise Linux (RHEL) 6.4 64-bit CloudPassage Halo
SUSE Linux 11 Enterprise Server 64-bit FlexConnector for REST
Oracle Solaris 10 64-bit Zscaler Nanolog Streaming Service (NSS)
IBM AIX version 7.1 64-bit
Content security
Anti-virus/Anti-spam Aladdin eSafe Gateway
F-Secure Anti-Virus Barracuda (NetContinuum Web Firewall)
Kaspersky Anti-Virus McAfee Email and Web Security Appliance
McAfee VirusScan Enterprise McAfee Web Gateway
Sophos Proofpoint Enterprise Protection and
Sybari Antigen for Microsoft Exchange Enterprise Privacy
Symantec Endpoint Protection Manager Puresight Content Filter
(SEPM) DB SEP 12 Secure Computing Webwasher
Symantec Mail Security for Microsoft Trend Micro Control Manager
Exchange Trend Micro InterScan Messaging Security
Trend Micro (TM) OfficeScan (Control (Control Manager)
Manager and TM Control Manager Trend Micro InterScan Web Security
Database[DB]) (Control Manager)
Multiple DB (Control Manager)
Database Activity Monitoring (DAM)/
Applications DBsecurity
IBM WebSphere Trustwave Application Security DbProtect
iT-CUBE agileSI SAP IBM InfoSphere Guardium
Oracle WebLogic Server (BEA) Imperva SecureSphere
SAP enterprise resource planning (ERP) Oracle (Secerno DataWall)
Microsoft SharePoint Server DB McAfee Sentrigo HedgeHog
(Enterprise and vPatch)
Data sheet | HP ArcSight SmartConnector
supportedproducts
Database IDS/IPSnetwork-based
IBM DB2 Broadweb NetKeeper
IBM DB2 UDB Audit File, version 10 Bro IDS
IBM DB2 UDB Audit File, Multiple Instance Bro IDS NG File
Microsoft SQL Cisco IPS Sensor
Oracle Audit DB Cisco Secure IDS
Oracle Audit Vault Cisco WIPS SNMP
Oracle Audit Syslog, version 11gR2 CounterSnipe
Oracle Audit XML11gR2 Enterasys Dragon
Sybase Adaptive Server Enterprise HP TippingPoint Security Management
System (SMS)
Data leak prevention IBM RealSecure Server Sensor
Fidelis XPS IBM RealSecure Workgroup Manager
GTB Inspector IBM Proventia IPS Appliance (SiteProtector)
McAfee Host Data Loss Prevention Juniper Networks IDP (NetScreen)
Endpoints (HDLP) McAfee Network Security Manager
Symantec DLP (Vontu) (Intru Shield)
Verdasys Digital Guardian NFR Central Management Server
NFR Security NID
Data security NitroSecurity IPS
CyberArk Inter-Business Vault PacketAlarm IDS
CyberArk Sensitive Document Vault Radware DefensePro
HP Atalla Network Security Snort
Processor(NSP) Sourcefire Intrusion Sensor
Ingrian Sourcefire Defense Center management
Vormetric Data Security Manager console
Vormetric Data Firewall Sourcefire Defense Center eStreamer,
JBoss Security Auditing File 7.1 version 5.0.2, 5.1
Sourcefire Real-time Network Awareness
Firewall (RNA) Sensor
Check Point FW-1 Top Layer Attack Mitigator
Cisco PIX Firewall
Cisco PIX/ASA Syslog, version 8.5, 8.6 IDM, IAM, and identity security
F5 BIG-IP Application Security Manager ActivCard AAA Server DB
Juniper Networks (Altor Networks RSA Aveksa
Virtual Firewall) BeyondTrust PowerBroker
Juniper Network Security Manager Cisco Secure Access Control Server (ACS)
(NetScreen) CyberArk Privileged Identity
Juniper Network Security Manager Syslog, Management (PIM) Suite
version 2011.4 CyberArk Privileged Session Management
Juniper Networks Firewall and VPN (PSM) Suite
Lucent Managed Firewall FoxT ServerControl
McAfee Desktop Firewall IBM Tivoli Access Manager
Secure Computing Gauntlet Firewall/VPN Juniper Steel-Belted Radius (SBR)
Lieberman Software Enterprise Random
Honeypot Password Manager (ERPM)
HoneyD Microsoft Active Directory
Microsoft Forefront
Intrusion Detection System and Intrusion Microsoft Forefront DB
Prevention Systemhost-based Microsoft Network Policy Server
IBM BlackICE Server Protection Novell Nsure Audit
(IBMSecurity SiteProtector System) ObserveIT Enterprise
NFR Security HID Oracle Sun ONE Directory Server
Symantec Critical System Protection VMware PacketMotion PacketSentry
Database Ping Identity PingFederate
Tripwire Manager Quest ChangeAuditor DB
Tripwire Enterprise RSA Authentication Manager
RSA Access Manager (ClearTrust)
Secure Computing SafeWord PremierAccess
Securonix
SpectorSoft Spector 360 Export Service
Thycotic Secret Server

2
Data sheet | HP ArcSight SmartConnector
supportedproducts
Integrated security FireEye Malware Protection
Barracuda Spam Firewall System(MPS)
Cisco ASA 5500 FireEye Mandiant Intelligent Response
Fortinet FortiGate Guidance EnCase
HP TippingPoint Next-Generation HBGary Active Defense
Firewall (NGFW) Lastline Enterprise
Palo Alto Networks PAN-OS Proofpoint NetCitadel ThreatOptics
Secure Computing Sidewinder TaaSera TaaS NetAnalyzer
SonicWALL Triumfant Resolution Manager
Stonesoft StoneGate
Network access control
IT operations ForeScout CounterACT
HP Operations Manager (OM and OMi) Mirage Networks CounterPoint
HP OpenView Operations (OVO) Portnox Portnox

Log consolidation and analysis Network behavior anomaly


Cisco Security Monitoring, Analysis, and Arbor Networks Peakflow
Response System (MARS) Lancope StealthWatch
Enterprise IT Security SF-RiskSaver Mazu Profiler
LOGbinder SP Qosmos DeepFlow Security
Quest InTrust (fka Aelita Event
Manager[AEM]) Network forensics
Qualys QualysGuard File, version 7.1 Narus nSystem
NIKSUN NetDetector
Mail filtering RSA NetWitness
Cisco IronPort Email Security Appliance AccessData CIRT
McAfee Email Gateway (Secure
Computing IronMail) Network management
McAfee Security for Email Servers CiscoWorks
(GroupShield) Cisco Wireless LAN Controller Syslog
MessageGate HP Network Node Manager i SNMP
Symantec Messaging Gateway Lumeta Enterprise Situational
(MailSecurity 8200 Series) Intelligence (ESI)
Lumeta IPsonar
Mainframe
CA Top Secret Network monitoring
Enterprise IT Security SF-Sherlock ISC DHCP
Enterprise IT Security SF-NoEvasion ISC BIND
IBM OS/390 (NVAS) Microsoft Operations Manager DB (MOM)
IBM OS/390 (SDSF) Microsoft System Center Operations
Helpsystems PowerTech Interact Manager (SCOM) DB
Type80 SMA_RT for RACF Microsoft System Center Configuration
Type80 SMA_RT for CA Top Secret Manager DB
IBM AS/400 Microsoft DHCP
Microsoft DNS
Mail server Microsoft WINS
IBM Lotus Notes Domino Enterprise Server
Microsoft Exchange Network traffic analysis
Microsoft Exchange PowerShell Cisco NetFlow/Flexible NetFlow
Microsoft Forefront for Exchange Server NetScout nGenius
Microsoft Forefront Protection Server FireEye nPulse Hammerhead
Management Console DB QoSient Argus
InMon sFlow
Malware detection Blue Coat Solera Networks DeepSee
AhnLab Malware Defense System (MDS) TCPdump
Damballa CSP
Damballa Failsafe Network traffic management
Cisco Distributed Director for Cisco 4500
Bro IDS

3
Data sheet | HP ArcSight SmartConnector
supportedproducts
Operating systems Virtualization
IBM AIX Operating System CounterTack Event Horizon
HP OpenVMS VMware ESX/ESXi Server
HP-UX Operating System VMware Virtual Center
HP-UX Syslog, version 11i v3
Microsoft Windows 7/NT/2000/2003/ VPN
XP/2008 Server/Vista Check Point VPN-1
Microsoft Windows Event Logunified, Cisco VPN Concentrator
SQL Server 2012 for SQL Server audit Citrix Access Gateway
Red Hat Linux Juniper/NetScreen (Neoteris) SSL VPN
Snare for Microsoft Windows Nortel Contivity Extranet Switch
Solaris Basic Security module (BSM)
UNIX Vulnerability assessment
SaberNet NTSyslog eEye REM Security Management Console
HP NonStop servers (XYPRO eEye Retina Network Security Scanner
Merged Audit) Harris STAT Scanner
IBM Internet Scanner
Packet capture McAfee Vulnerability Manager (FoundScan)
Ixia Anue Net Tool Optimizer nCircle IP360 Device Profiler
nCircle IP360 Threat Monitor
Physical systems/security Nmap
RedCloud (PlaSec) Open Vulnerability and Assessment
Language (OVAL) Standard
Policy management QualysGuard
McAfee Policy Auditor Rapid 7 Nexpose
NetIQ Security Manager Tenable Nessus
Solsoft Policy Server SAINT Vulnerability Scanner

Router Web cache


Cisco Router Blue Coat Proxy SG Series
Juniper Router (JUNOS) Microsoft Internet Security and
HP H3C Comware Platform Acceleration(ISA)
Squid Web Proxy Cache
Security management
Enterasys Dragon Server Web filtering
IBM SiteProtector Cisco IronPort Web Security Appliance
iSIGHT ThreatScape API Websense Web Security Suite
Lookingglass ScoutVision
McAfee ePolicy Orchestrator (ePO) Web server
McAfee Network Security Manager DB Apache
McAfee Rogue System Detection (via ePO) Microsoft Internet Information Services (IIS)
Microsoft Audit Collection Services Sun ONE
Network Vulnerability Advisor
Symantec Enterprise Security Wireless
Manager(ESM) AirDefense Guard
AirMagnet Enterprise
Storage AirTight SpectraGuard
NetApp filer (FAS) Aruba WLAN Mobility Controller
EMC Celerra Cisco Mobility Services Engine

Switch
Cisco Catalyst
Cisco CSS 11500 Series Content
ServicesSwitches
Cisco NX-OS
For additional information on HP ArcSight Foundry Networks BigIron
SmartConnector, visit the user community HP Ethernet switch
website on Protect724 (need Protect724 login): HP Networking Syslog
protect724.hp.com/community/arcsight/
productdocs/connectors.

4
Data sheet | HP ArcSight SmartConnector
supportedproducts

HP ArcSight SmartConnector list


The HP ArcSight library of out-of-the-box SmartConnectors provides source-optimized
collection for leading security vendor commercial products. These products span the entire
stack of event-generating source types, from network and security devices to databases and
enterprise applications. Company/Product is the default listing in this document but it links to
the overall SmartConnector and CEF documents.

ActivCard AAA Server DB eEye REM Security Management Console


AirDefense Guard eEye Retina Network Security Scanner
AirMagnet Enterprise EMC Celerra
Aladdin eSafe Gateway Enterasys Dragon
Apache Enterasys Dragon Server
Arbor Networks Peakflow FlexConnector for REST
Aruba WLAN Mobility Controller Fortinet FortiGate
Barracuda Spam Firewall Foundry Networks BigIron
Barracuda (NetContinuum Web Firewall) F-Secure Anti-Virus
Blue Coat Proxy SG Series Harris STAT Scanner
Box HP Ethernet switch
Bro IDS HP H3C Comware Platform
Bro IDS NG File HP OVO
Broadweb NetKeeper HP OpenVMS
CA Top Secret HP OM and OMi
CentOS HP Networking Syslog
Check Point FW-1 HP TippingPoint SMS
Check Point VPN-1 HP-UX Operating System
Cisco ASA 5500 HP-UX Syslog, version 11i v3
Cisco Catalyst IBM AIX Operating System
Cisco CSS 11500 Series Content IBM AIX version 7.1, 64-bit
ServicesSwitches IBM BlackICE Server Protection
Cisco Distributed Director 4500 IBM DB2
Cisco IPS Sensor IBM DB2 UDB Audit File, Multiple Instance
Cisco IronPort Email Security Appliance IBM DB2 UDB Audit File, version 10
Cisco IronPort Web Security Appliance IBM Internet Scanner
Cisco Security MARS IBM Lotus Notes Domino Enterprise Server
Cisco Mobility Services Engine IBM OS/390 (NVAS)
Cisco NetFlow/Flexible NetFlow IBM OS/390 (SDSF) Type80 SMA_RT
Cisco NX-OS forRACF
Cisco PIX Firewall IBM Proventia IPS Appliance (SiteProtector)
Cisco PIX/ASA Syslog, version 8.5, 8.6 IBM RealSecure Server Sensor
Cisco Router IBM RealSecure Workgroup Manager
Cisco ACS IBM Security SiteProtector System
Cisco Secure IDS IBM SiteProtector
Cisco Security Agent (Okena) IBM Tivoli Access Manager
Cisco WIPS SNMP IBM WebSphere
Cisco Wireless LAN Controller Syslog Ingrian
CiscoWorks InMon sFlow
Citrix Access Gateway ISC BIND
CounterSnipe ISC DHCP
HP Network Node Manager i SNMP JBoss Security Auditing File 7.1

5
Data sheet | HP ArcSight SmartConnector
supportedproducts
Juniper Network Security Manager Microsoft Operations Manager (MOM) DB
(NetScreen) Microsoft SharePoint Server DB
Juniper Network Security Manager Syslog, Microsoft SQL
version 2011.4 Microsoft System Center Configuration
Juniper Networks Firewall and VPN Manager DB
Juniper Networks IDP (NetScreen) Microsoft SCOM DB
Juniper Router (JUNOS) Microsoft Windows 7/NT/2000/2003/
Juniper SBR XP/2008 Server/Vista
Juniper/NetScreen (Neoteris) SSL VPN Microsoft Windows Event Logunified SQL
Kaspersky Anti-Virus Server 2012 for SQL Server audit
Lucent Managed Firewall Microsoft Windows Server 2003 R2 (SP2)
Mazu Profiler 32/64-bit
McAfee Application Control (Solidcore) Microsoft Windows
McAfee Desktop Firewall Server 2008 R2 SP1 64-bit
McAfee Email Gateway (Secure Microsoft Windows
Computing IronMail) Server 2008 SP2 32/64-bit
McAfee ePO Microsoft Windows
McAfee HDLP Server 2012 Standard 64-bit
McAfee Network Security Manager Microsoft Windows XP Professional
(Intru Shield) (SP3)32-bit
McAfee Network Security Manager DB Microsoft WINS
McAfee Policy Auditor Mirage Networks CounterPoint
McAfee Rogue System Detection (via ePO) nCircle IP360 Device Profiler
McAfee Security for Email Servers nCircle IP360 Threat Monitor
(GroupShield) NetApp filer (FAS)
McAfee VirusScan Enterprise NetIQ Security Manager
McAfee Vulnerability Manager (FoundScan) NFR Central Management Server
McAfee Web Gateway NFR Security HID
MessageGate NFR Security NID
Microsoft Active Directory NitroSecurity IPS
Microsoft Audit Collection Services Nmap
Microsoft DHCP Nortel Contivity Extranet Switch
Microsoft DNS Novell Nsure Audit
Microsoft Exchange Oracle Audit DB
Microsoft Exchange PowerShell Oracle Audit Syslog, version 11gR2
Microsoft Forefront Oracle Audit Vault
Microsoft Forefront DB Oracle Audit XML11gR2
Microsoft Forefront for Exchange Server Oracle Solaris 10, 64-bit
Microsoft Forefront Protection Server Oracle Sun ONE Directory Server
Management Console DB Oracle WebLogic Server (BEA)
Microsoft IIS OVAL
Microsoft ISA PacketAlarm IDS
Microsoft Network Policy Server Proofpoint Enterprise Protection and
(WindowsIAS/RADIUS) Enterprise Privacy

6
Data sheet | HP ArcSight SmartConnector
supportedproducts
Puresight Content Filter Sun ONE
QoSient Argus SUSE Linux 11 Enterprise Server 64-bit
QualysGuard Sybari Antigen for Microsoft Exchange
Qualys QualysGuard File, version 7.1 Sybase Adaptive Server Enterprise
Quest ChangeAuditor DB Symantec Critical System Protection
Quest InTrust (fka AEM) Database
Radware DefensePro Symantec DLP (Vontu)
Rapid 7 Nexpose SEPM DB SEP 12
RHEL 6.4 64-bit Symantec ESM
Red Hat Linux Symantec Mail Security for
RSA Access Manager (ClearTrust) MicrosoftExchange
RSA Authentication Manager Symantec Messaging Gateway
SaberNet NTSyslog (MailSecurity 8200 Series)
SAINT Vulnerability Scanner TCPdump
SAP ERP Tenable Nessus
Secure Computing Gauntlet Firewall/VPN Top Layer Attack Mitigator
Secure Computing SafeWord PremierAccess Trend Micro Control Manager
Secure Computing Sidewinder Trend Micro InterScan Messaging Security
Secure Computing Webwasher (Control Manager)
Snare for Microsoft Windows Trend Micro InterScan Web Security
Snort (Control Manager)
Solaris BSM Trend Micro OfficeScan (Control Manager
Solsoft Policy Server and TM Control Manager DB)
SonicWALL Trend Micro VirusWall (Control Manager)
Sophos Type80 SMA_RT for CA Top Secret
Sourcefire Defense Center eStreamer, UNIX
version 5.0.2, 5.1 VMware ESX/ESXi Server
Sourcefire Defense Center management VMware Virtual Center
console Vormetric Data Security Manager
For additional information on HP ArcSight Sourcefire Intrusion Sensor Websense Web Security Suite
SmartConnector, visit the user community Sourcefire RNA Sensor
website on Protect724 (need Protect724 login): Squid Web Proxy Cache
protect724.hp.com/community/arcsight/
productdocs/connectors.

7
Data sheet | HP ArcSight SmartConnector
supportedproducts

HP ArcSight CEF/Action connector list


In addition to SmartConnectors developed and maintained by HP ArcSight, we test and certify
the following 81 connector types through our Technology Alliance Program:
CEF Certifiedhelps ensure event information is captured properly in the CEF
Action Certifiedallows for control of a vendors technology from within the HP ArcSight Console

Action Certified solutions: CEF Certified solutions: Juniper Networks (Altor Networks
RSA Aveksa AccessData CIRT Virtual Firewall)
CyberArk PSM Suite AhnLab MDS Lancope StealthWatch
ForeScout CounterACT AirTight SpectraGuard Lastline Enterprise Anti-Malware
Guidance EnCase Arxan GuardIT Lieberman Software ERPM
Ixia Anue Net Tool Optimizer BeyondTrust PowerBroker LOGbinder SP
FireEye Mandiant Intelligent Response Bit9 Parity Lookingglass ScoutVision
Proofpoint NetCitadel ThreatOptics CA Layer 7 SecureSpan/CloudSpan Gateway Lumeta ESI
FireEye nPulse Hammerhead CloudPassage Halo Lumeta IPsonar
Securonix RTI CorreLog dbDefender McAfee Email and Web Security Appliance
Blue Coat Solera DeepSee CounterTack Event Horizon McAfee Sentrigo HedgeHog (Enterprise
Verdasys Digital Guardian CyberArk Inter-Business Vault and vPatch)
CyberArk PIM Suite McAfee Stonesoft StoneGate
CyberArk Sensitive Document Vault Narus nSystem
Damballa CSP NetScout nGenius
Damballa Failsafe Network Vulnerability Advisor
Enterprise IT Security SF-NoEvasion NIKSUN NetDetector
Enterprise IT Security SF-RiskSaver ObserveIT Enterprise
Enterprise IT Security SF-Sherlock Oracle (Secerno DataWall)
F5 BIG-IP Application Security Manager Palo Alto Networks PAN-OS
FairWarning Ping Identity PingFederate
FireEye Mandiant Intelligent Response Proofpoint NetCitadel ThreatOptics
FireEye MPS Portnox Portnox
ForeScout CounterACT Qosmos DeepFlow Security
FoxT ServerControl RedCloud (PlaSec)
General Dynamics Fidelis XPS RSA NetWitness
GTB Inspector RSA Silver Tail Systems Forensics
HBGary Active Defense Securonix RTI
Helpsystems PowerTech Interact SpectorSoft Spector 360 Export Service
HP Atalla NSP TaaSera TaaS NetAnalyzer
HP NonStop servers (XYPRO Merged Audit) Thycotic Secret Server
HP TippingPoint NGFW Tripwire Manager & Tripwire Enterprise
IBM InfoSphere Guardium Triumfant Resolution Manager
Imperva SecureSphere Trustwave Application Security DbProtect
iSIGHT ThreatScape API Verdasys Digital Guardian
iT-CUBE agileSI SAP VMware PacketMotion PacketSentry
Vormetric Data Firewall
Zscaler NSS

Sign up for updates


hp.com/go/getupdated Share with colleagues Rate this document

Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only
warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein
should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.
McAfee is a trademark or registered trademark of McAfee, Inc. in the United States and other countries. Microsoft, Windows, Windows 7, Windows XP,
Windows NT, Windows Vista, and Windows Server are trademarks of the Microsoft Group of companies. Oracle is a registered trademark of Oracle
and/or its affiliates. RedHat is a registered trademark of Red Hat, Inc. in the United States and other countries. SAP is the trademark or registered
trademark of SAP SE in Germany and in several other countries. UNIX is a registered trademark of The Open Group. Citrix is a registered trademark of
Citrix Systems, Inc. and/or one more of its subsidiaries, and may be registered in the United States Patent and Trademark Office and in other countries.
Linux is the registered trademark of Linus Torvalds in the U.S. and other countries. VMware is a registered trademark or trademark of VMware, Inc. in the
United States and/or other jurisdictions.
4AA5-3404ENW, October 2014, Rev. 2

Anda mungkin juga menyukai