Cisco Security and Micro Focus ArcSight

How Micro Focus ArcSight and Cisco Security work together

Product Integrations

CloudLock: Together, CloudLock and ArcSight empower security teams to better analyze and understand risk in cloud environments and the organization at large. ArcSight collects event data from CloudLock.

ISE: ArcSight part of ISE SIEM ecosystem is using Syslog. ArcSight team is looking to add a remediation feature via pxGrid.

Secure Firewall: Micro Focus' ArcSight SIEM uses the Cisco Firepower Management Center's eStreamer API to collect and parse event data into its platform for analysis and archiving. Most customers use a community-supported eStreamer client available on GitHub. The client converts eStreamer data into a CEF format for easy ingestion by ArcSight.

Secure Firewall ASA: ArcSight collects ASA’s syslog event data

Useful links