Aqua Security - 2.5 - CEF - Integration - Guide - 2018
Aqua Security - 2.5 - CEF - Integration - Guide - 2018
Aqua Security - 2.5 - CEF - Integration - Guide - 2018
2
ArcSight Integration Guide
This document is provided for informational purposes only, and the information herein is subject to change
without notice. Please report any errors herein to Micro Focus. Micro Focus does not provide any warranties
covering this information and specifically disclaims any liability in connection with this document.
Certified Integration:
The integration complies with the requirements of the Micro Focus Technology Alliance Partner program. For
inbound integrations, the Micro Focus ArcSight CEF connector will be able to process the events correctly and
the events will be available for use within Micro Focus’ ArcSight product. In addition, the event content has
been deemed to be in accordance with standard SmartConnector requirements. For action and outbound
integrations, the integration establishes outbound communications from Micro Focus ArcSight to a third party
platform. The integration has been tested and demonstrated to Micro Focus by the third party.
Revision History
Date Description
3
Aqua Integration Integration Guide
This guide provides information for configuring Aqua Container Security Platform (CSP) for syslog event
collection. This integration is supported on Linux platforms. Device versions starting Aqua Security version 2.5
and above at any machine running Docker version 1.13 or above.
The joint solution combining Micro Focus ArcSight platform and Aqua CSP allows users to share all the Docker
related commands and vulnerabilities information between Aqua CSP and Micro Focus ArcSight. This results in
automated risk management and real time context view for the container environment
Use Cases
This section describes important use cases supported by this integration.
• Monitor Docker related events & container run time actions
• Monitor Common Vulnerabilities and Exposure (CVE) found in images and containers
Monitor Common Vulnerabilities and Exposure (CVE) found in images and container
Organization should constantly monitor that all applications are properly patched with software updates and
feed the application patch status information into the ArcSight solution.
Use Aqua CSP to continuously scan images for vulnerabilities and send information to ArcSight to continuously
monitor patching process and status.
4
CEF Integration
5
2. Events
DeviceEventClassIds:
366 - Administration (Administration related commands, e.g create user, remove user, add policy, etc)
367 - Docker commands (events related to docker, e.g pull, create, start, stop, etc)
368 - Runtime events (events from inside the containers, e.g rm, exec, unlink, connect, accept, etc)
369 - Image Assurance (events related to Image Vulnerabilities)
Vendor-Specific Event
Field Name Vendor- Specific Event Name Definition ArcSight Event Data Field
6
Vendor-Specific Event
Field Name Vendor- Specific Event Name Definition ArcSight Event Data Field
Prerequisites
Product Name Version Information Operating System
Support
Integration support information when an issue is outside of the ArcSight team’s scope
In some cases the ArcSight customer service team is unable to help with issues that lie within the configuration
itself in which case the certified vendor should be contacted for assistance:
7
Additional ArcSight Documentation
For more information about the joint solution, visit the Micro Focus ArcSight Marketplace:
https://marketplace.microfocus.com/arcsight/category/partner-integrations For more
information about Micro Focus Security ArcSight ESM:
https://software.microfocus.com/en-us/software/siem-security-information-event-management