Configuration Management Best Practices
Configuration management is a powerful tool for managing multiple ArcSight products. You can easily implement configurations across managed products with just a few actions.
-
Node management versus Configuration Management: Use ArcSight Management Center’s node management tools for the administration of individual nodes and their day-to-day operations. However, for consistent and wide-ranging changes to the data or settings of managed nodes, use configuration management if the appropriate configuration exists. For example, to change DNS settings across multiple managed nodes, it would be faster and easier to create the configuration in ArcMC and push it out to managed nodes, than to individually change the settings across multiple devices.
-
Implementing data settings across multiple appliances or products in bulk: Use the Bulk Management (Set Configuration) tools to implement data settings across multiple appliances or products. For example, you can quickly configure all of your appliances to use the same hardware settings (such as SMTP server) with a single platform (in this case, SMTP) configuration applied to managed nodes. (Pushing will overwrite any existing data.)
- Compliance versus Non-Compliance: If configuration compliance is not relevant to your configuration management, use the bulk management tools under Node Management to manage your node settings. A bulk push can also be performed under Configuration Management.