The ArcSight Activate L1 - Application Monitoring Web Services - Indicators and Warnings package has been developed to detect anomalies and suspicious requests that are recorded in web server logs that may not be visible to other protective measures such as IDS/IPS and WAF due to the use of encrypted transport. In addition, the package provides a set of HTTP request method and response code filters supported by the HTTP Protocol to monitor possible DoS HTTP flooding attacks, as well as identifies some suspicious XSS and SQL injection attacks.It also can provide indicators and warnings of potential security incidents at the application level, such as L1 Application Monitoring Web Applications or other packages.
The L1 Application Monitoring Web Services - Indicators and Warnings package has addressed the following use cases
Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.
Included new use cases to monitor web server logs:
Now the package also supports MITRE Framework.
Micro Focus rebranding changes
Related content and resources
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox