<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35581" language="de" source="https://portal.flane.ch/swisscom/xml-course/opentext-aesma" lastchanged="2025-07-29T12:18:44+02:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>ArcSight Enterprise Security Manager Administration</title><productcode>AESMA</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-AESMA</fullproductcode><version>24.1</version><objective>&lt;p&gt;On completion of this course, participants should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identify the ESM communication strategy used between the various devices and components within an ESM Network&lt;/li&gt;&lt;li&gt;Define each ESM operation modes and components, Compact and Distributed, and the issues ESM Distributed Mode comes to solve&lt;/li&gt;&lt;li&gt;Plan, install, and run ESM in Distributed Mode&lt;/li&gt;&lt;li&gt;Identify functions and navigate the Command Center UI&lt;/li&gt;&lt;li&gt;Install and customize the ESM console&lt;/li&gt;&lt;li&gt;Install and configure ArcSight SmartConnectors&lt;/li&gt;&lt;li&gt;Install and configure a Forwarding Connector&lt;/li&gt;&lt;li&gt;Setup Notifications&lt;/li&gt;&lt;li&gt;Import Zone and Asset information with the Network Model wizard&lt;/li&gt;&lt;li&gt;Customize ArcSight ESM using the properties files&lt;/li&gt;&lt;li&gt;Describe and install ArcSight upgrades and patches&lt;/li&gt;&lt;li&gt;Create Users and define User Permissions&lt;/li&gt;&lt;li&gt;Review Administrator Reports, Dashboards and Filters&lt;/li&gt;&lt;li&gt;Configure and manage storage groups&lt;/li&gt;&lt;li&gt;Describe CORRE daily job archives&lt;/li&gt;&lt;li&gt;Recognize how to Back up and restore ESM&lt;/li&gt;&lt;li&gt;Describe and deploy uses of SSL technology in ArcSight ESM&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful in this course, you should have the following prerequisites or knowledge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Knowledge of ESM Concepts&lt;/li&gt;&lt;li&gt;(Minimum) 6 Months ArcSight Administration Experience&lt;/li&gt;&lt;li&gt;Database SQL statements experience&lt;/li&gt;&lt;li&gt;Linux Administration experience&lt;/li&gt;&lt;li&gt;Successful Completion of ArcSight ESM Administrator &amp;amp; Analyst Course or Equivalent Experience&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;This course is for Administrators who install, maintain, and troubleshoot ESM components&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Design and implement integrations between ArcSight ESM and other ArcSight products&lt;/li&gt;&lt;li&gt;Proactively investigate the health of the ESM CORRE environment.&lt;/li&gt;&lt;/ul&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Introduction to ESM Administration&lt;/li&gt;&lt;li&gt;ESM Distributed Components&lt;/li&gt;&lt;li&gt;Installing ESM Distributed Mode&lt;/li&gt;&lt;li&gt;Maintaining ESM Properties Files and Upgrades&lt;/li&gt;&lt;li&gt;Installing the ESM Console&lt;/li&gt;&lt;li&gt;Installing SmartConnectors&lt;/li&gt;&lt;li&gt;Managing the Network Model&lt;/li&gt;&lt;li&gt;Configuring SmartConnector Destinations&lt;/li&gt;&lt;li&gt;Installing the ESM Super and Syslog Connectors&lt;/li&gt;&lt;li&gt;SmartConnectors Configurations and Advanced Features&lt;/li&gt;&lt;li&gt;Command Center&lt;/li&gt;&lt;li&gt;Accessing Administrator Content&lt;/li&gt;&lt;li&gt;Content Management and Peering&lt;/li&gt;&lt;li&gt;ESM User Administration and Notification&lt;/li&gt;&lt;li&gt;ESM Certification Management&lt;/li&gt;&lt;li&gt;ESM Backup and Restore&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Module 1: Introduction to ESM Administration&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe each ESM system component&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2: ESM Distributed Components&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Recognize where ESM fits within the ArcSight Architecture&lt;/li&gt;&lt;li&gt;Define each ESM operation modes, Compact and Distributed, and the issues ESM Distributed Mode comes to solve&lt;/li&gt;&lt;li&gt;Describe the ESM Distributed Mode components&lt;/li&gt;&lt;li&gt;Recognize the ArcSight Data Platform (ADP) and its components&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3: Installing ESM Distributed Mode&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Plan System Hardware Requirements&lt;/li&gt;&lt;li&gt;Check Operating System Pre-Installation&lt;/li&gt;&lt;li&gt;Install ESM Persistor Node&lt;/li&gt;&lt;li&gt;Install ESM Correlator Aggregator Node&lt;/li&gt;&lt;li&gt;Configure Integration of the Persistor Node&lt;/li&gt;&lt;li&gt;Add Correlator Aggregator Services&lt;/li&gt;&lt;li&gt;Configure Message Bus Data and Control Instances from Persistor&lt;/li&gt;&lt;li&gt;Configure Repository Instances from Persistor&lt;/li&gt;&lt;li&gt;Configure Distributed Cache on Correlator Aggregators&lt;/li&gt;&lt;li&gt;Run Cert Admin Approveall&lt;/li&gt;&lt;li&gt;Start All Cluster Wide Services from Persistor Node&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4: Maintaining ESM Properties Files and Upgrades&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Customize ArcSight ESM using Properties File&lt;/li&gt;&lt;li&gt;Prepare System for an Upgrade&lt;/li&gt;&lt;li&gt;Upgrade ESM&lt;/li&gt;&lt;li&gt;Upgrade the ESM Console&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 5: Installing the ESM Console&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Install the ESM Console&lt;/li&gt;&lt;li&gt;Customize the ESM Console&lt;/li&gt;&lt;li&gt;Describe Tools available in the ESM Console&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 6: Installing SmartConnectors&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe how Connectors collect, normalize, and cache events&lt;/li&gt;&lt;li&gt;Install and configure ArcSight SmartConnectors&lt;/li&gt;&lt;li&gt;Identify Connector Command Scripts&lt;/li&gt;&lt;li&gt;Describe how Connectors can be managed from an ESM Console, a Connector Appliance, or ArcSight Management Center&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 7: Managing the Network Model&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;List Network Model resources&lt;/li&gt;&lt;li&gt;Describe Asset Model resources&lt;/li&gt;&lt;li&gt;Add the following modelling resources:&lt;/li&gt;&lt;li&gt;Assets&lt;/li&gt;&lt;li&gt;Asset Ranges&lt;/li&gt;&lt;li&gt;Zones&lt;/li&gt;&lt;li&gt;Network and attach it to a connector&lt;/li&gt;&lt;li&gt;Import Zone and Asset information with the Network Model wizard&lt;/li&gt;&lt;li&gt;Explain the use of the Asset Import Connector&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 8: Configuring SmartConnector Destinations&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Get SmartConnector Status&lt;/li&gt;&lt;li&gt;Set SmartConnector Flow-Control&lt;/li&gt;&lt;li&gt;Use SmartConnector Administrative Dashboards&lt;/li&gt;&lt;li&gt;Configure SmartConnectors for Failover and Dual Destinations&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 9: Installing the ESM Super and Syslog Connectors&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Installing and configure a Forwarding Connector&lt;/li&gt;&lt;li&gt;Installing and configure a Syslog connector&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 10: SmartConnectors Configurations and Advanced Features&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Configuring SmartConnectors using advanced features such as turbo mode, map files, event filtering, network options and event aggregation&lt;/li&gt;&lt;li&gt;Constructing advanced configuration settings for optimal performance and data enrichment&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 11: Command Center&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Logging onto the ArcSight Command Center&lt;/li&gt;&lt;li&gt;Identifying functions and navigate the User Interface&lt;/li&gt;&lt;li&gt;Using the ArcSight Command Center Help Facility&lt;/li&gt;&lt;li&gt;Configure:&lt;/li&gt;&lt;li&gt;Authentication&lt;/li&gt;&lt;li&gt;Content&lt;/li&gt;&lt;li&gt;Storage&lt;/li&gt;&lt;li&gt;Appliances&lt;/li&gt;&lt;li&gt;Identifying stock content dashboards&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 12: Accessing Administrator Content&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Reviewing Administrator Reports, Dashboards and Filters&lt;/li&gt;&lt;li&gt;Running and Archiving Reports&lt;/li&gt;&lt;li&gt;Using Administrator Data Monitors&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 13: Content Management and Peering&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Peering ESMS&lt;/li&gt;&lt;li&gt;Performing Peer Searches&lt;/li&gt;&lt;li&gt;Creating Packages and Pushing content to a Peer&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 14: ESM User Administration and Notification&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Creating Users and setting User Notifications&lt;/li&gt;&lt;li&gt;Managing Resource Permissions&lt;/li&gt;&lt;li&gt;Accessing and Modifying Password Properties&lt;/li&gt;&lt;li&gt;Configuring ArcSight Notifications&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 15: ESM Certification Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describing uses of SSL technology in ArcSight ESM&lt;/li&gt;&lt;li&gt;Describing SSL setup options&lt;/li&gt;&lt;li&gt;Keytool/keytoolgui&lt;/li&gt;&lt;li&gt;Certadmin&lt;/li&gt;&lt;li&gt;Identifying the steps to deploy:&lt;/li&gt;&lt;li&gt;Self-signed Certificates&lt;/li&gt;&lt;li&gt;Approve/revoke distributed mode Certificates&lt;/li&gt;&lt;li&gt;CA (Certificate Authority)-signed Certificates&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 16: ESM Backup and Restore&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Restoring the ESM Manager&amp;rsquo;s configurations&lt;/li&gt;&lt;li&gt;Backing up and restoring ESM&lt;/li&gt;&lt;li&gt;Describing CORR-E Daily Job Archiving&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>On completion of this course, participants should be able to:


- Identify the ESM communication strategy used between the various devices and components within an ESM Network
- Define each ESM operation modes and components, Compact and Distributed, and the issues ESM Distributed Mode comes to solve
- Plan, install, and run ESM in Distributed Mode
- Identify functions and navigate the Command Center UI
- Install and customize the ESM console
- Install and configure ArcSight SmartConnectors
- Install and configure a Forwarding Connector
- Setup Notifications
- Import Zone and Asset information with the Network Model wizard
- Customize ArcSight ESM using the properties files
- Describe and install ArcSight upgrades and patches
- Create Users and define User Permissions
- Review Administrator Reports, Dashboards and Filters
- Configure and manage storage groups
- Describe CORRE daily job archives
- Recognize how to Back up and restore ESM
- Describe and deploy uses of SSL technology in ArcSight ESM</objective_plain><essentials_plain>To be successful in this course, you should have the following prerequisites or knowledge:


- Knowledge of ESM Concepts
- (Minimum) 6 Months ArcSight Administration Experience
- Database SQL statements experience
- Linux Administration experience
- Successful Completion of ArcSight ESM Administrator &amp; Analyst Course or Equivalent Experience</essentials_plain><audience_plain>This course is for Administrators who install, maintain, and troubleshoot ESM components


- Design and implement integrations between ArcSight ESM and other ArcSight products
- Proactively investigate the health of the ESM CORRE environment.</audience_plain><contents_plain>- Introduction to ESM Administration
- ESM Distributed Components
- Installing ESM Distributed Mode
- Maintaining ESM Properties Files and Upgrades
- Installing the ESM Console
- Installing SmartConnectors
- Managing the Network Model
- Configuring SmartConnector Destinations
- Installing the ESM Super and Syslog Connectors
- SmartConnectors Configurations and Advanced Features
- Command Center
- Accessing Administrator Content
- Content Management and Peering
- ESM User Administration and Notification
- ESM Certification Management
- ESM Backup and Restore</contents_plain><outline_plain>Module 1: Introduction to ESM Administration


- Describe each ESM system component
Module 2: ESM Distributed Components


- Recognize where ESM fits within the ArcSight Architecture
- Define each ESM operation modes, Compact and Distributed, and the issues ESM Distributed Mode comes to solve
- Describe the ESM Distributed Mode components
- Recognize the ArcSight Data Platform (ADP) and its components
Module 3: Installing ESM Distributed Mode


- Plan System Hardware Requirements
- Check Operating System Pre-Installation
- Install ESM Persistor Node
- Install ESM Correlator Aggregator Node
- Configure Integration of the Persistor Node
- Add Correlator Aggregator Services
- Configure Message Bus Data and Control Instances from Persistor
- Configure Repository Instances from Persistor
- Configure Distributed Cache on Correlator Aggregators
- Run Cert Admin Approveall
- Start All Cluster Wide Services from Persistor Node
Module 4: Maintaining ESM Properties Files and Upgrades


- Customize ArcSight ESM using Properties File
- Prepare System for an Upgrade
- Upgrade ESM
- Upgrade the ESM Console
Module 5: Installing the ESM Console


- Install the ESM Console
- Customize the ESM Console
- Describe Tools available in the ESM Console
Module 6: Installing SmartConnectors


- Describe how Connectors collect, normalize, and cache events
- Install and configure ArcSight SmartConnectors
- Identify Connector Command Scripts
- Describe how Connectors can be managed from an ESM Console, a Connector Appliance, or ArcSight Management Center
Module 7: Managing the Network Model


- List Network Model resources
- Describe Asset Model resources
- Add the following modelling resources:
- Assets
- Asset Ranges
- Zones
- Network and attach it to a connector
- Import Zone and Asset information with the Network Model wizard
- Explain the use of the Asset Import Connector
Module 8: Configuring SmartConnector Destinations


- Get SmartConnector Status
- Set SmartConnector Flow-Control
- Use SmartConnector Administrative Dashboards
- Configure SmartConnectors for Failover and Dual Destinations
Module 9: Installing the ESM Super and Syslog Connectors


- Installing and configure a Forwarding Connector
- Installing and configure a Syslog connector
Module 10: SmartConnectors Configurations and Advanced Features


- Configuring SmartConnectors using advanced features such as turbo mode, map files, event filtering, network options and event aggregation
- Constructing advanced configuration settings for optimal performance and data enrichment
Module 11: Command Center


- Logging onto the ArcSight Command Center
- Identifying functions and navigate the User Interface
- Using the ArcSight Command Center Help Facility
- Configure:
- Authentication
- Content
- Storage
- Appliances
- Identifying stock content dashboards
Module 12: Accessing Administrator Content


- Reviewing Administrator Reports, Dashboards and Filters
- Running and Archiving Reports
- Using Administrator Data Monitors
Module 13: Content Management and Peering


- Peering ESMS
- Performing Peer Searches
- Creating Packages and Pushing content to a Peer
Module 14: ESM User Administration and Notification


- Creating Users and setting User Notifications
- Managing Resource Permissions
- Accessing and Modifying Password Properties
- Configuring ArcSight Notifications
Module 15: ESM Certification Management


- Describing uses of SSL technology in ArcSight ESM
- Describing SSL setup options
- Keytool/keytoolgui
- Certadmin
- Identifying the steps to deploy:
- Self-signed Certificates
- Approve/revoke distributed mode Certificates
- CA (Certificate Authority)-signed Certificates
Module 16: ESM Backup and Restore


- Restoring the ESM Manager’s configurations
- Backing up and restoring ESM
- Describing CORR-E Daily Job Archiving</outline_plain><duration unit="d" days="5">5 Tage</duration><pricelist><price country="DE" currency="EUR">4000.00</price></pricelist><miles/></course>