You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/integrations/arcsight.md
+5-7Lines changed: 5 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,23 +13,23 @@ This article describes how to send Microsoft Defender for IoT alerts to ArcSight
13
13
14
14
Before you begin, make sure that you have the following prerequisites:
15
15
16
-
- Access to a Defender for IoT OT sensor, version TBD or higher. Make sure that you can sign in as a TBD user.
17
-
18
-
- Access to an ArcSight server as a TBD user.
16
+
- Access to a Defender for IoT OT sensor as an Admin user.
19
17
20
18
## Configure the ArcSight receiver type
21
19
22
-
This procedure describes how to TBD.
20
+
To configure your ArcSight server settings so that it can receive Defender for IoT alert information:
23
21
24
22
1. Sign in to your ArcSight server.
25
23
1. Configure your receiver type as a **CEF UDP Receiver**.
26
24
27
-
For more information, see TBD.
25
+
For more information, see the [ArcSight SmartConnectors Documentation](https://www.microfocus.com/documentation/arcsight/arcsight-smartconnectors/#gsc.tab=0).
28
26
29
27
## Create a Defender for IoT forwarding rule
30
28
31
29
This procedure describes how to create a forwarding rule from your OT sensor to send Defender for IoT alerts from that sensor to ArcSight.
32
30
31
+
For more information, see [Forward alert information](../how-to-forward-alert-information-to-partners.md).
32
+
33
33
1. Sign in to your OT sensor console and select **Forwarding** on the left.
34
34
35
35
1. Enter a meaningful name for your rule, and then define your rule details, including:
@@ -38,8 +38,6 @@ This procedure describes how to create a forwarding rule from your OT sensor to
38
38
- The protocols you want to include in the rule.
39
39
- The traffic you want to include in the rule.
40
40
41
-
For more information, see [Forward alert information](../how-to-forward-alert-information-to-partners.md).
42
-
43
41
1. In the **Actions** area, define the following values:
0 commit comments