Configuring Audit Forwarding to a Specific Destination

You can forward audit and system health events to an ArcSight ESM destination for correlation and analysis, and to Logger for event collection.

To forward audit events to specific destinations:

  1. Click Setup > System Admin from the top-level menu bar.

  2. Click Audit Forwarding in the Logs section.

  3. Select destinations from the Available Destinations list and click the right arrow icon () to move the selected destination to the Selected Destinations list.

    You can select multiple destinations at the same time and move them, or you can move all available destinations by clicking the () icon.

  4. Click Save Settings.

    Note: For software ArcMC, the following is required:

    • The audit event forwarding connector needs to be installed under the /opt/arcsight/connector directory.

    • During the installation, on the Connector Detail page, please input data for all fields, and continue with the installation process.