The ArcSight manager is a correlation engine, therefore it is desirable to have it correlate events from as many different security devices as possible. One common logging method is to send high-volume support events, such as DNS, DHCP and Proxy, to the ArcSight Loggers and then bring specific items into the manager when an alert is triggered.

An example of this would be when IDS and firewall events are not all sent to ArcSight Manager but reside in the ArcSight Logger. This API would help with a search of the Loggers for a specified IDS alert of activity permitted to a host and bring in the related parameter events for a rule that triggers.

Network security is greatly enhanced as this tool saves Analysts valuable time and allows them to investigate more events in a shorter period.


  • Search for events on any Logger.
  • Search any time period.
  • Limit number of returned events.
  • Use simple or complex search conditions including regex.
  • Three program modes.
    • Run from command line on Linux or Windows.
    • Use in ArcSight Integration commands.
    • Use in ArcSight rule actions.
  • Four ways to process events.
    • Display events on screen
    • Write events to file.
    • Send CEF events to Syslog server.
    • Send CEF events to ArcSight Syslog Connector.

Suggested apps

Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.


Date 7.0
18.4 MB
Oct 7, 2015
More info Less info

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the Micro Focus Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.

Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2021-2-3-3805 | Wed Feb 24 23:06:24 PST 2021