Managing Destinations

Connectors can forward events to more than one destination, such as ArcSight Manager and ArcSight Logger. You can assign one or more destinations per connector. You can assign multiple destinations to a connector and specify a failover (alternate) destination in the event that the primary destination fails.

The following procedures describe how to perform these actions on a specific connector or for multiple connectors at the same time:

Adding a Primary Destination to a Connector

When you add a primary destination to a connector, you need to enter details for the destination, such as the destination hostname and port used.

To add a primary destination to a connector:

  1. Click Node Management.

  2. In the navigation tree, browse to the connector to which you wish to add a destination. In the management panel, the Connector summary tab displays.

  3. On the Connector summary tab, next to Destinations, click . The Add Destination wizard starts.

  4. Follow the steps in the wizard. You can either select an existing destination or add a new destination. If you are adding a new destination, select the destination type and enter parameters for the destination. Destination types are described in the SmartConnector User's Guide.

    Note: For containers running 5.1.2.5823 and later, ArcSight Management Center retrieves the certificate for the ArcSight Manager destination automatically and displays the certificate summary.

    For containers running 5.1.2 and earlier, upload the certificate on the container and then add the destination.

    FIPS Suite B certificates are not retrieved automatically and must be uploaded manually.

    To see certificate details, hover over the certificate.

    • Select Import the certificate to the connector from the destination, and then click Next to import the certificate and continue.

    • Select Do not import the certificate to the connector from the destination and click Next if you do not want to import the certificate. The destination will not be added.

  5. Click Done when complete.

Adding a Failover Destination to a Connector

Each destination can have a failover destination in case the connection with the primary destination fails.

Tip: UDP connections cannot detect transmission failure. Use Raw TCP for CEF Syslog destinations.

To add a failover destination to a connector:

  1. Click Node Management.

  2. In the navigation tree, browse to the connector to which you wish to add a destination. In the management panel, the Connector summary tab displays.

  3. On the Connector summary tab, in the Destinations table, click . The Add Destination wizard starts.

  4. Follow the steps in the wizard to select from available destinations and enter the destination details.

    Note: FIPS Suite B certificates are not retrieved automatically and must be uploaded manually.

    To see certificate details, hover over the certificate.

    • Select Import the certificate to the connector from the destination, and then click Next to import the certificate and continue.

    • Select Do not import the certificate to the connector from the destination and click Next if you do not want to import the certificate. The destination will not be added.

  5. Click Done when complete.

Adding a Primary or Failover Destination to Multiple Connectors

You can add a primary or failover destination to several connectors at the same time.

To add a primary or failover destination to multiple connectors:

  1. Click Node Management.

  2. In the navigation tree, browse to the container where the connectors reside.

  3. In the management panel, click the Connectors tab.

  4. From the list of connectors, select all connectors to which you wish to assign a destination.

  5. Click Destinations. The Manage Destinations wizard launches.

  6. Review the dialog, and then click Next.

  7. Under Choose an Option, select Add a destination, and then click Next.

  8. Choose between creating a new destination or selecting an existing destination, and then click Next.

    • If you choose to create a new destination, select the destination type and then provide the destination parameters. Destination types are described in the SmartConnector User's Guide.

    • If you choose to select an existing destination, select a destination from the list.

      Note: ArcSight Management Center retrieves the ArcSight Manager certificate for the destination automatically and displays the certificate summary.

      FIPS Suite B certificates are not retrieved automatically and must be uploaded manually.

      To see certificate details, hover over the certificate.

      • Select Import the certificate to the connector from destination, and then click Next to import the certificate and continue.

      • Select Do not import the certificate to the connector from the destination and click Next if you do not want to import the certificate. The destination will not be added.

  9. Define the destination function by choosing between a primary or failover destination.

    • If you choose Primary destination, click Next to update the configuration.

    • If you choose Failover destination:

      1. Select the primary destination that applies to your failover.

      2. Check the box in the table header to modify all of the displayed connectors.

      3. Click Next to update the configuration.

  10. Click Done when complete.

Removing Destinations

You can remove a destination from a connector at any time. Each connector must have at least one destination; as a result, you may not remove all destinations from a connector.

To remove destinations from one or more connectors:

  1. Click Node Management.

  2. In the navigation tree, browse to the container where the connectors reside.

  3. In the management panel, click the Connectors tab.

  4. From the list of connectors, select all connectors to which you wish to remove a destination.

  5. Click Destinations. The Manage Destinations wizard launches.

  6. Review the dialog, and then click Next.

  7. Under Choose an Option, select Remove a destination, and then click Next.

  8. Follow the instructions in the wizard, and click Done when complete.

Re-Registering Destinations

At certain times, you might need to re-register the destinations for one or more connectors; for example, after you upgrade ESM, or if a Logger appliance or ESM appliance becomes unresponsive.

To re-register destinations for one or more connectors:

  1. Click Node Management.

  2. In the navigation tree, browse to the container where the connectors reside.

  3. In the management panel, click the Connectors tab.

  4. From the list of connectors, select all connectors to which you wish to assign a destination.

  5. Click Destinations. The Manage Destinations wizard launches.

  6. Review the dialog, and then click Next.

  7. Under Choose an Option, select Re-register destinations, and then click Next.

  8. Follow the instructions in the wizard and click Done when complete.

Editing Destination Parameters

The following procedures describe how to edit destination parameters for a specific connector and how to edit destination parameters for multiple connectors.

Note: When enabling the demo CA for one or more connectors, use the Certificate button, instead of editing the ESM destination.

To edit destination parameters for a connector:

  1. Click Node Management.

  2. In the navigation tree, browse to the connector to which you wish to edit destination parameters. In the management panel, the Connector summary tab displays.

  3. In the Destinations table, click next to the destination you want to edit to display the Edit Destination Parameters page.

  4. Make your changes, and then click Next.

  5. Click Done when complete.

To edit destination parameters for multiple connectors:

  1. Click Node Management.

  2. In the navigation tree, browse to the container where the connectors reside.

  3. In the management panel, click the Connectors tab.

  4. From the list of connectors, select all connectors for which you wish to edit destination parameters.

  5. Click Destinations. The Manage Destinations wizard opens.

  6. Review the dialog, and then click Next.

  7. Under Choose an Option, select Edit a destination, and then click Next.

  8. Follow the instructions in the wizard and click Done when complete.

Editing Destination Runtime Parameters

The runtime parameters for a destination enable you to specify advanced processing options such as batching, time correction, and bandwidth control. The parameters you can configure are listed in Destination Runtime Parameters . The user interface automatically displays the parameters valid for a destination.

The following procedures describe how to edit the runtime parameters for a specific connector and how to edit the runtime parameters for multiple connectors at the same time.

To edit destination runtime parameters for a connector:

  1. Click Node Management.

  2. In the navigation tree, browse to the connector for which you wish to edit destination runtime parameters. In the management panel, the Connector summary tab displays.

  3. On the Connector summary tab, in the Destinations table, click next to the destination whose runtime parameters you want to edit.

  4. Under Add Alternate Configurations, click next to the alternate configuration that you want to edit.

    If you have not set up alternate configurations, click next to the Default. For more information about alternate configurations, see Managing Alternate Configurations .

  5. Specify or update values for the listed parameters, and then click Save.

To edit destination runtime parameters for multiple connectors at the same time:

  1. Click Node Management.

  2. In the navigation tree, browse to the container where the connectors reside.

  3. In the management panel, click the Connectors tab.

  4. From the list of connectors, select all connectors for which you wish to edit destination runtime parameters.

  5. Click Runtime Parameters to open the wizard.

  6. Follow these steps in the wizard to edit the runtime parameters:

    1. Select the destinations whose runtime parameters you want to modify.

    2. Select the configurations to be affected (default or alternate configurations).

    3. Select the group of parameters you want to modify (for example, batching, cache, network, processing).

    4. Modify the parameters.

Managing Alternate Configurations

An alternate configuration is a set of runtime parameters that is used instead of the default configuration during a specified portion of every day. For example, you might want to specify different batching schemes (by severity or size) for different times of a day. You can define more than one alternate configuration per destination, and apply them to the destination for different time ranges during the day. For example, you can define a configuration for 8 a.m. to 5 p.m. time range and another configuration for the 5 p.m. to 8 a.m. time range.

By default, a configuration labeled Default is applied to a destination. Any subsequent configurations you define are labeled Alternate#1, Alternate#2, and so on. The default configuration is used if the time ranges specified for other alternate configurations do not span 24 hours. For example, if you specify an alternate configuration, Alternate#1 that is effective from 7 a.m. to 8 p.m., the Default configuration is used from 8 p.m. to 7 a.m.

If you need to apply the same alternate configuration for multiple destinations, you need to define an alternate configuration (with the same settings) for each of those destinations.

Defining a New Alternate Configuration

The process of defining a new alternate configuration includes first defining the configuration, and then editing it to specify the time range for which that configuration is effective.

To define an alternate configuration:

  1. Click Node Management.

  2. In the navigation tree, browse to the connector for which you wish to edit destination runtime parameters. In the management panel, the Connector summary tab displays.

  3. On the Connector summary tab, in the Destinations table, click .

  4. Under Add Alternate Configurations, click Add.

  5. Specify or update values for the listed parameters.

  6. Click Save. If this is the first alternate configuration you defined, it is saved as Alternate#1. Subsequent configurations are saved as Alternate#2, Alternate#3, and so on.

    To specify the effective time range for which the configuration you just defined, edit the configuration you just defined using the following procedure, Editing an Alternate Configuration.

Editing an Alternate Configuration

In addition to editing an alternate configuration to change parameter values, you can edit it to specify the time range for which it is effective.

To edit an alternate configuration:

  1. Click Node Management.

  2. In the navigation tree, browse to the connector for which you wish to edit destination runtime parameters. In the management panel, the Connector summary tab displays.

  3. On the Connector summary tab, in the Destinations table, click .

  4. From the list of alternate configurations, select the alternate configuration that you want to edit, and then click .

  5. Specify or update values for the listed parameters, including the time range in the From Hour/To Hour.

  6. Scroll down to the end of the page and click Save.

Editing Alternate Configurations in Bulk

If you need to update the same parameters in multiple alternate configurations, follow the procedure described in Editing Destination Runtime Parameters.

Sending a Command to a Destination

You can send a command to a connector destination.

To send a command to a destination on a connector:

  1. Click Node Management.

  2. In the navigation tree, browse to the connector for which you wish to send a command. In the management panel, the Connector summary tab displays.

  3. On the Connector summary tab, in the Destinations table, click .

  4. Select the command you want to run, and then click Next.

  5. Enter values for the parameters that the user interface displays, and then click Finish.