User`s guide

Technical white paper
HP CloudSystem Enterprise
Integrating security with HP ArcSight
Table of contents
Executive summary ...................................................................................................................................................................... 3
HP CloudSystem Enterprise overview ...................................................................................................................................... 3
HP CloudSystem Enterprise supply layer ............................................................................................................................ 3
HP CloudSystem Enterprise demand and delivery: HP Cloud Service Automation .................................................... 3
HP CloudSystem Enterprise components ........................................................................................................................... 4
HP ArcSight overview ................................................................................................................................................................... 4
Enterprise Security Manager .................................................................................................................................................. 4
HP ArcSight Logger ................................................................................................................................................................... 5
HP ArcSight Connectors ........................................................................................................................................................... 5
Typical deployment scenarios .................................................................................................................................................... 6
Sending events in RAW and CEF format to HP ArcSight Logger ..................................................................................... 6
Sending events to HP ArcSight Logger using Connectors ............................................................................................... 7
Sending events to HP ArcSight ESM using Connectors ..................................................................................................... 8
Devices ........................................................................................................................................................................................ 9
Grouping devices ....................................................................................................................................................................... 9
Forwarding events to HP ArcSight ESM.............................................................................................................................. 10
Protecting HP CloudSystem Enterprise components with HP ArcSight .......................................................................... 11
Cloud Service Automation 3.1 .............................................................................................................................................. 12
Matrix Operating Environment ............................................................................................................................................. 13
Server Automation .................................................................................................................................................................. 15
VMware ESXi 5 Host ............................................................................................................................................................... 15
Networking ............................................................................................................................................................................... 21
HP TippingPoint Security Management System (SMS) Appliance ................................................................................ 22
Protecting CloudSystem Enterprise Services with HP ArcSight ........................................................................................ 25
HP LAMP solution .................................................................................................................................................................... 25
Working with events ................................................................................................................................................................... 27
Searching the HP ArcSight Logger ...................................................................................................................................... 27
HP ArcSight ESM Viewing Events with Active Channels ............................................................................................... 29
Zones ......................................................................................................................................................................................... 31
Queries ...................................................................................................................................................................................... 31
Rules .......................................................................................................................................................................................... 34
Cloud Security Alliance ............................................................................................................................................................... 35
Summary ....................................................................................................................................................................................... 36

Summary of content (39 pages)