<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35286" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/opentext-asfcc" lastchanged="2025-07-29T12:18:36+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>ArcSight FlexConnector Configuration</title><productcode>ASFCC</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-ASFCC</fullproductcode><version>7.6</version><objective>&lt;p&gt;On completion of this course, participants should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Install ArcSight Connector software, configure a functional FlexConnector, and test with an ESM Active Channel&lt;/li&gt;&lt;li&gt;Use the FlexConnector Wizard to create fixed delimited configuration files&lt;/li&gt;&lt;li&gt;Use the Regex Tester tool to create common and sub-message parsing and token-to-event mapping&lt;/li&gt;&lt;li&gt;Create a tailored Categorization file for a parent FlexConnector and test its function in an active channel&lt;/li&gt;&lt;li&gt;Navigate the connector configuration file hierarchy to locate, display and edit&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful in this course, you should have the following prerequisites or knowledge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Successful completion of ArcSight ESM Admin and Analyst course&lt;/li&gt;&lt;li&gt;Successful completion of ArcSight ESM Advanced Administrator course&lt;/li&gt;&lt;li&gt;Working knowledge of Regular Expressions&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Security administrators, content authors/architects, and IT integrators, who build and install custom connectors to provide critical event data feeds to ArcSight ESM or Logger, Senior analysts for networks, security systems, enterprise applications and databases&lt;/p&gt;</audience><contents>&lt;h5&gt;Module 1: Introduction to FlexConnector&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Define SmartConnectors and their functions&lt;/li&gt;&lt;li&gt;Follow device deployment and the event flow processing&lt;/li&gt;&lt;li&gt;Describe FlexConnectors types&lt;/li&gt;&lt;li&gt;Install a Connector&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2: Using ArcSight Schema&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Gather event requirements prior to developing your FlexConnector&lt;/li&gt;&lt;li&gt;Normalize and map events&lt;/li&gt;&lt;li&gt;Differentiate special cases&lt;/li&gt;&lt;li&gt;List the different schema groups&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3: Basic Configuration File and Categorization&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Locate FlexConnector files&lt;/li&gt;&lt;li&gt;Define the configuration procedure&lt;/li&gt;&lt;li&gt;Apply the four steps to create a FlexConnector configuration file
&lt;ul&gt;
&lt;li&gt;Parser configuration&lt;/li&gt;&lt;li&gt;Token declaration&lt;/li&gt;&lt;li&gt;Event mapping&lt;/li&gt;&lt;li&gt;Severity mapping&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Use the FlexConnector wizard to install a configuration file&lt;/li&gt;&lt;li&gt;Utilize Categorization to profile an event
&lt;ul&gt;
&lt;li&gt;Six criteria are used: Object, Behavior, Outcome, Technique, Device Group, and Significance&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4: Regex FlexConnectors&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Install the Regex File Reader FlexConnector&lt;/li&gt;&lt;li&gt;Create common Regex&lt;/li&gt;&lt;li&gt;Define SubMessages&lt;/li&gt;&lt;li&gt;Use the Regex Tester Introduction into the concept of Teams&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 5: Installing ESM Syslog Connectors with Custom Parsers&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Identify the syslog Connectors&lt;/li&gt;&lt;li&gt;Describe the syslog FlexConnector components&lt;/li&gt;&lt;li&gt;Create the syslog FlexConnector configuration file&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 6: JSON Folder Follower Connector&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Identify the properties of basic JSON objects&lt;/li&gt;&lt;li&gt;Define Token and Mappings declarations for a JSON Folder Follower FlexConnector&lt;/li&gt;&lt;li&gt;Perform installation and testing of a JSON Folder Follower FlexConnector in console mode&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 7: Advanced Topics&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the purposes of multi-line Regex configuration parameters:
&lt;ul&gt;
&lt;li&gt;Concatenate lines belonging to a single event&lt;/li&gt;&lt;li&gt;Identify the start and/or end of each event&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Describe parser linking when two or more FlexConnector types may be needed to parse the same data&lt;/li&gt;&lt;li&gt;Define and create conditional mapping configurations&lt;/li&gt;&lt;li&gt;Illustrate the LogFu tool which reads and parses ArcSight logs and generates interactive visual presentations of them&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>On completion of this course, participants should be able to:


- Install ArcSight Connector software, configure a functional FlexConnector, and test with an ESM Active Channel
- Use the FlexConnector Wizard to create fixed delimited configuration files
- Use the Regex Tester tool to create common and sub-message parsing and token-to-event mapping
- Create a tailored Categorization file for a parent FlexConnector and test its function in an active channel
- Navigate the connector configuration file hierarchy to locate, display and edit</objective_plain><essentials_plain>To be successful in this course, you should have the following prerequisites or knowledge:


- Successful completion of ArcSight ESM Admin and Analyst course
- Successful completion of ArcSight ESM Advanced Administrator course
- Working knowledge of Regular Expressions</essentials_plain><audience_plain>Security administrators, content authors/architects, and IT integrators, who build and install custom connectors to provide critical event data feeds to ArcSight ESM or Logger, Senior analysts for networks, security systems, enterprise applications and databases</audience_plain><contents_plain>Module 1: Introduction to FlexConnector


- Define SmartConnectors and their functions
- Follow device deployment and the event flow processing
- Describe FlexConnectors types
- Install a Connector
Module 2: Using ArcSight Schema


- Gather event requirements prior to developing your FlexConnector
- Normalize and map events
- Differentiate special cases
- List the different schema groups
Module 3: Basic Configuration File and Categorization


- Locate FlexConnector files
- Define the configuration procedure
- Apply the four steps to create a FlexConnector configuration file

- Parser configuration
- Token declaration
- Event mapping
- Severity mapping
- Use the FlexConnector wizard to install a configuration file
- Utilize Categorization to profile an event

- Six criteria are used: Object, Behavior, Outcome, Technique, Device Group, and Significance
Module 4: Regex FlexConnectors


- Install the Regex File Reader FlexConnector
- Create common Regex
- Define SubMessages
- Use the Regex Tester Introduction into the concept of Teams
Module 5: Installing ESM Syslog Connectors with Custom Parsers


- Identify the syslog Connectors
- Describe the syslog FlexConnector components
- Create the syslog FlexConnector configuration file
Module 6: JSON Folder Follower Connector


- Identify the properties of basic JSON objects
- Define Token and Mappings declarations for a JSON Folder Follower FlexConnector
- Perform installation and testing of a JSON Folder Follower FlexConnector in console mode
Module 7: Advanced Topics


- Describe the purposes of multi-line Regex configuration parameters:

- Concatenate lines belonging to a single event
- Identify the start and/or end of each event
- Describe parser linking when two or more FlexConnector types may be needed to parse the same data
- Define and create conditional mapping configurations
- Illustrate the LogFu tool which reads and parses ArcSight logs and generates interactive visual presentations of them</contents_plain><duration unit="d" days="3">3 days</duration><pricelist><price country="DE" currency="EUR">2400.00</price></pricelist><miles/></course>