ArcSight System Monitor Content v.0
ArcSight System Monitor Content v.0
ArcSight System Monitor Content v.0
Session List
Monitor Type : SessionListMonitor
Attribute Name : SessionCacheInformation
Smart Connector
Monitor Type : AgentStateTracker
Attribute Name : HeartbeatState
Attribute Name : AgentStatuses
Attribute Name : AgentsFilter
Attribute Name : ManagerStatistics
Attribute Name : ManagerThroughputs
Monitor Type : SeededJsseListener
Attribute Name : OngoingSessions
Asset
Resource Memory Usage
Monitor Type : CapsManager
Attribute Name : MemoryUsageInfo
Attribute Name : MemoryLimit
Database Transactions
Monitor Type : DBSecurityEventBroker
Attribute Name : SideObjectCacheStatistics
Attribute Name : SideObjectManagerStatistics
Attribute Name : SideObjectFloodStatistics
Attribute Name : SideObjectPerAgentStats
Data Monitor
Monitor Type : FilterOptimizedXCPUDMPC
Attribute Name : ProbeStats
Attribute Name : ProbeTypeStats
License
Monitor Type : LicenseInfo
Attribute Name : LicenseInfoSummary
Error Log
Task Scheduler
Monitor Type : Scheduler
Attribute Name : TaskQueue
Rules
Monitor Type : RulesEngine
Attribute Name : LoadedRules
User
Report
ESM Resource Audit Events
General Resource Updates
Smart Connector
User Authentication
Actor
Archive
Active Channel
License
Content Management
Group Management
Pattern Discovery
Query Viewer
Report
Trend
Resource Quota
Rule
Scheduler
Session List
User Login
ESM Health Monitoring Example Scenarios
ESM Manager
‘Event Throughput’ Dashboard Check
Compare the ‘current’ event rates (EPS/EPD) with what the architecture was ‘originally sized’
for regularly.
If the customer has outgrown the architecture, make recommendations in the Architecture
Review section of the Health Check Report.
Check for any Network Latency Issues between ur Agents and Manager and update ur
Manager/Agent Settings to avoid caching and events dropping.
Enable Load Balancing in Agent Setup to avoid conflicts in Performance and Data Loss.
o
Hardware and OS Check
Is there sufficient CPU Cores and Memory?
Is there sufficient Disk Space for Archives?
Is the Operating System requires any patching/upgrade?
Error Check
• Review both.../manager/logs/default/server.std.log and server.log for ERROR and WARN
messages
o tail -f server.log | grep -v INFO (exclude INFO messages)
o Review the MostRecentErrorLogRecords of LogManager for the Recent Errors
Logged
o Utilize the ‘arcsight exceptions’ command:
<ARCSIGHT_HOME>/bin/arcsight exceptions –n
<ARCSIGHT_HOME>/logs/default/*.log*
o Review the ‘System Events’ Active Channel for High and Very-High system events
Scheduled Task Check
• Verify that scheduled tasks don’t conflict with each other
• Heavy Tasks should be scheduled during off hours
• Are there any failed jobs?
Logger
Connector
Up/Down Check and Version Check
Check the Connector Status Dashboard for the Latest Connector Version.
Logs Check
../current/logs/agent.out.wrapper.log
• Java Heap Memory Utilization
o Memory utilization
o Frequency of Full GCs
o Memory in Red Zone alerts
• Unexpected Restarts
• Time zone errors
• Connectivity Errors
o End Devices
o ArcSight Destinations
o Certificate Errors
../current/logs/agent.log
o Parsing errors
o DOSProtector
o WARN and ERROR messages
o Custom Override Details
Configuration Check
Destination Settings
Common problems found:
o No Networks and Customer
o Poor Fields-based Aggregation
o No Filter applied on high EPS Connectors
o Non consistent Settings
Reference:
ESM Administration Guide
ESM User Guide Audit Events
Tip: A Lot of useful Contents Found in Community Forum like one below:
https://protect724.hp.com/docs/DOC-1877
Next Release with more on Fine Tuning Steps and Advanced ESM System Content Management and
Detailed Troubleshooting Steps with Individual Resource Breakdowns.