<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="33455" language="de" source="https://portal.flane.ch/swisscom/xml-course/opentext-arc4300i" lastchanged="2025-07-29T12:18:23+02:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>Installing and Configuring ArcSight Platform</title><productcode>ARC4300I</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-ARC4300I</fullproductcode><version>23.2</version><objective>&lt;p&gt;On completion of this course, participants should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the ArcSight Platform and its Architecture&lt;/li&gt;&lt;li&gt;Describe the system requirements&lt;/li&gt;&lt;li&gt;Install ArcSight Platform&lt;/li&gt;&lt;li&gt;Verify a successful installation&lt;/li&gt;&lt;li&gt;Configure ArcSight Platform to ingest events&lt;/li&gt;&lt;li&gt;Configure collectors and CTH with ArcMC&lt;/li&gt;&lt;li&gt;Configure Topics and Routes&lt;/li&gt;&lt;li&gt;Configure ESM and SOAR Integration&lt;/li&gt;&lt;li&gt;Manage ArcSight Users&lt;/li&gt;&lt;li&gt;Enable Single Sign-On&lt;/li&gt;&lt;li&gt;Add features to an existing ArcSight installation&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful in this course, you should have the following prerequisites or knowledge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;ESM200 - ESM Administrator and Analyst or comparable ArcSight experience&lt;/li&gt;&lt;li&gt;Experience working with command line tools&lt;/li&gt;&lt;li&gt;Experience deploying applications in Windows and Linux environments&lt;/li&gt;&lt;li&gt;Computer desktop, browser, and file system navigation skills&lt;/li&gt;&lt;li&gt;Two Monitors to make it easy to review the guides on one screen, and the lab on the second screen&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;This course is designed for Security Professionals and SOC Administrators, who are responsible for deploying and administrating the ArcSight Platform within their environment.&lt;/p&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Architecture&lt;/li&gt;&lt;li&gt;System Requirements&lt;/li&gt;&lt;li&gt;YAML Files&lt;/li&gt;&lt;li&gt;Installing ArcSight Platform&lt;/li&gt;&lt;li&gt;Post-Install Activities&lt;/li&gt;&lt;li&gt;Transformation Hub Management from Fusion ArcMC&lt;/li&gt;&lt;li&gt;Producing Events and Transformation Hub Ingestion&lt;/li&gt;&lt;li&gt;Collectors and CTH Deployment from ArcMC&lt;/li&gt;&lt;li&gt;Topic and Route Management&lt;/li&gt;&lt;li&gt;Integrating ESM and SOAR&lt;/li&gt;&lt;li&gt;Enabling Single Sign-On&lt;/li&gt;&lt;li&gt;Managing Users in ArcSight&lt;/li&gt;&lt;li&gt;Adding More ArcSight Capabilities&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Module 1: Architecture&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describing the ArcSight Platform and its Architecture&lt;/li&gt;&lt;li&gt;Describing the underlying CDF infrastructure&lt;/li&gt;&lt;li&gt;Identifying the ArcSight Platform Capabilities&lt;/li&gt;&lt;li&gt;Explaining other related components to the Platform&lt;/li&gt;&lt;li&gt;Considerations and Best Practices&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2: System Requirements&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describing the following:
&lt;ul&gt;
&lt;li&gt;System Requirements&lt;/li&gt;&lt;li&gt;Host Requirements&lt;/li&gt;&lt;li&gt;DNS requirements&lt;/li&gt;&lt;li&gt;NFS Requirements&lt;/li&gt;&lt;li&gt;ArcSight Database&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3: YAML Files&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Configuring the ArcSight Platform YAML Files&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4: Installing ArcSight Platform&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Pre-installing ArcSight&lt;/li&gt;&lt;li&gt;Installing ArcSight&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 5: Post-Install Activities&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Checking the status of the ArcSight Platform Installation&lt;/li&gt;&lt;li&gt;Accessing and exploring the ITOM Management Portal&lt;/li&gt;&lt;li&gt;Running the post-install command to finalize the deployment&lt;/li&gt;&lt;li&gt;Uploading License Files under the ITOM Management Portal&lt;/li&gt;&lt;li&gt;Logging into Fusion for the First Time&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 6: Transformation Hub Management from Fusion ArcMC&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Validating a successful integration between Transformation Hub and the new containerized ArcMC available in Fusion&lt;/li&gt;&lt;li&gt;Retrieving the master root certificate&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 7: Producing Events and Transformation Hub Ingestion&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Recognizing and describing how events are produced&lt;/li&gt;&lt;li&gt;Describing event formats: classic (CEF) and AVRO&lt;/li&gt;&lt;li&gt;Installing a CEF Producer and AVRO Producer of events&lt;/li&gt;&lt;li&gt;Detailed walkthrough of the configuration steps and all parameters&lt;/li&gt;&lt;li&gt;Sending Test Alerts Replay Events to Transformation Hub&lt;/li&gt;&lt;li&gt;Validating Topics and Transformation Hub Ingestion&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 8: Collectors and CTH Deployment from ArcMC&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining the difference between a Collector and Connector&lt;/li&gt;&lt;li&gt;Listing the advantages of using Collectors&lt;/li&gt;&lt;li&gt;Describing what&amp;rsquo;s needed to perform a Collector Deployment using ArcMC&lt;/li&gt;&lt;li&gt;Deploying CTH from ArcMC and route events from th-syslog to other topics&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 9: Topic and Route Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Managing Topic and Routes&lt;/li&gt;&lt;li&gt;Local vs Global Event Enrichment&lt;/li&gt;&lt;li&gt;Types of Stream Processor Instances in Transformation Hub&lt;/li&gt;&lt;li&gt;Configuring Topics and Routes &amp;ndash; Step by Step Example for Global Event Enrichment&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 10: Integrating ESM and SOAR&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Configuring the ESM and SOAR Integration&lt;/li&gt;&lt;li&gt;Verifying a Successful Integration&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 11: Enabling Single Sign-On&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Configuring the ESM Admin User for Single Sign-on&lt;/li&gt;&lt;li&gt;Enabling Single Sign-on&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 12: Managing Users in ArcSight&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Managing ArcSight Users Overview&lt;/li&gt;&lt;li&gt;Managing ESM Users&lt;/li&gt;&lt;li&gt;Managing Fusion Users&lt;/li&gt;&lt;li&gt;Managing SOAR Users&lt;/li&gt;&lt;li&gt;Defining Recon User Permissions and Roles&lt;/li&gt;&lt;li&gt;Defining Intelligence User Permissions and Roles&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 13: Adding More ArcSight Capabilities&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describing the benefits of adding more ArcSight capabilities&lt;/li&gt;&lt;li&gt;Adding more ArcSight capabilities&lt;/li&gt;&lt;li&gt;Specify mandatory filtering on pre-defined fields or user-specified fields&lt;/li&gt;&lt;li&gt;Create lookup values for field attributes&lt;/li&gt;&lt;li&gt;Create and use parameters and parameter groups&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>On completion of this course, participants should be able to:


- Describe the ArcSight Platform and its Architecture
- Describe the system requirements
- Install ArcSight Platform
- Verify a successful installation
- Configure ArcSight Platform to ingest events
- Configure collectors and CTH with ArcMC
- Configure Topics and Routes
- Configure ESM and SOAR Integration
- Manage ArcSight Users
- Enable Single Sign-On
- Add features to an existing ArcSight installation</objective_plain><essentials_plain>To be successful in this course, you should have the following prerequisites or knowledge:


- ESM200 - ESM Administrator and Analyst or comparable ArcSight experience
- Experience working with command line tools
- Experience deploying applications in Windows and Linux environments
- Computer desktop, browser, and file system navigation skills
- Two Monitors to make it easy to review the guides on one screen, and the lab on the second screen</essentials_plain><audience_plain>This course is designed for Security Professionals and SOC Administrators, who are responsible for deploying and administrating the ArcSight Platform within their environment.</audience_plain><contents_plain>- Architecture
- System Requirements
- YAML Files
- Installing ArcSight Platform
- Post-Install Activities
- Transformation Hub Management from Fusion ArcMC
- Producing Events and Transformation Hub Ingestion
- Collectors and CTH Deployment from ArcMC
- Topic and Route Management
- Integrating ESM and SOAR
- Enabling Single Sign-On
- Managing Users in ArcSight
- Adding More ArcSight Capabilities</contents_plain><outline_plain>Module 1: Architecture


- Describing the ArcSight Platform and its Architecture
- Describing the underlying CDF infrastructure
- Identifying the ArcSight Platform Capabilities
- Explaining other related components to the Platform
- Considerations and Best Practices
Module 2: System Requirements


- Describing the following:

- System Requirements
- Host Requirements
- DNS requirements
- NFS Requirements
- ArcSight Database
Module 3: YAML Files


- Configuring the ArcSight Platform YAML Files
Module 4: Installing ArcSight Platform


- Pre-installing ArcSight
- Installing ArcSight
Module 5: Post-Install Activities


- Checking the status of the ArcSight Platform Installation
- Accessing and exploring the ITOM Management Portal
- Running the post-install command to finalize the deployment
- Uploading License Files under the ITOM Management Portal
- Logging into Fusion for the First Time
Module 6: Transformation Hub Management from Fusion ArcMC


- Validating a successful integration between Transformation Hub and the new containerized ArcMC available in Fusion
- Retrieving the master root certificate
Module 7: Producing Events and Transformation Hub Ingestion


- Recognizing and describing how events are produced
- Describing event formats: classic (CEF) and AVRO
- Installing a CEF Producer and AVRO Producer of events
- Detailed walkthrough of the configuration steps and all parameters
- Sending Test Alerts Replay Events to Transformation Hub
- Validating Topics and Transformation Hub Ingestion
Module 8: Collectors and CTH Deployment from ArcMC


- Defining the difference between a Collector and Connector
- Listing the advantages of using Collectors
- Describing what’s needed to perform a Collector Deployment using ArcMC
- Deploying CTH from ArcMC and route events from th-syslog to other topics
Module 9: Topic and Route Management


- Managing Topic and Routes
- Local vs Global Event Enrichment
- Types of Stream Processor Instances in Transformation Hub
- Configuring Topics and Routes – Step by Step Example for Global Event Enrichment
Module 10: Integrating ESM and SOAR


- Configuring the ESM and SOAR Integration
- Verifying a Successful Integration
Module 11: Enabling Single Sign-On


- Configuring the ESM Admin User for Single Sign-on
- Enabling Single Sign-on
Module 12: Managing Users in ArcSight


- Managing ArcSight Users Overview
- Managing ESM Users
- Managing Fusion Users
- Managing SOAR Users
- Defining Recon User Permissions and Roles
- Defining Intelligence User Permissions and Roles
Module 13: Adding More ArcSight Capabilities


- Describing the benefits of adding more ArcSight capabilities
- Adding more ArcSight capabilities
- Specify mandatory filtering on pre-defined fields or user-specified fields
- Create lookup values for field attributes
- Create and use parameters and parameter groups</outline_plain><duration unit="d" days="5">5 Tage</duration><pricelist><price country="FR" currency="EUR">3750.00</price><price country="DE" currency="EUR">4000.00</price></pricelist><miles/></course>