Arcsight - architecture .
Arcsight - architecture .
ArcSight solution
Paul Brettle – Presales Manager, Americas Pacific Region
#HPProtect
© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
What is high availability?
3 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
What is disaster recovery?
Disaster recovery (DR) involves a set of policies and procedures to enable the
recovery or continuation of vital technology infrastructure and systems following
a natural or human-induced disaster.
• [1] Disaster recovery focuses on the IT or technology systems supporting critical business functions
Critical differentiation
• What do I need?
• How do I approach it?
• What is the minimum that I will accept?
4 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
But what is high availability?
5 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Prioritize and organize
6 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
What do I get by default?
Communications
• Reliable communications
Cache
• Built in once collected for all SmartConnectors
Commit
• Commit model for storage of data (SmartConnector -> ESM)
Recovery
• Archive files
Hardware
• Dual power supply, reliable hardware, hot swap components and storage
7 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
ArcSight Architecture
ArcSight Logger Instance
Connector
Appliance
Analysts (Optional)
Manager Database SAN
browser to access ESM, Events of interest will be forwarded from Logger to ESM
Logger, and CA. for real-time correlation. Correlated events will be
forwarded back to Logger for long-term storage.
ArcSight Logger Instances (2+)
Connector
Logger Logger
Analysts Appliance
Loggers are configured in a Peer Network.
Events from all
SmartConnectors will be
forwarded to separate Loggers
for load balancing purposes.
All SmartConnectors are
ArcSight ArcSight ArcSight ArcSight ArcSight ArcSight ArcSight ArcSight ArcSight managed remotely via the
AUP Master ArcSight Connector Appliance.
SmartConnectors SmartConnectors SmartConnectors
9 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
ArcSight Architecture
Analysts will leverage the ArcSight Console Globally correlated and base events will be
or a web browser to access the Global or forwarded from the Global ESM Instance to All SmartConnectors are managed remotely
Regional ESM and Logger Instances. Logger for long-term storage. via the ArcSight Connector Appliance.
11 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Connector layer
ArcSight Logger/Express/ESM
12 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Log storage layer
Logger DR site Main Logger
13 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Log storage layer
Storage device used for
Logger DR site
archived daily logs. Secondary
• Warm standby model Logger can retrieve archives
as necessary.
• Backup configuration
Configuration restored to
• Access archives access stored data and Main Logger
assume role of main Logger.
• Provide cache at connectors
14 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Log storage layer
• Be aware of network
Connector
Connector
15 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Correlation layer
Here a primary Manager is used
Primary as the single processing server
• ESM with Oracle Manager for the correlation etc. of the ESM
solution. All communications to
– Simple fail-over to single DB the database come from the
single primary Manager.
– Use commercial solutions
– Tried and trusted
16 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Correlation layer
• Consider ESM/Express
Replication
• Look at options
ArcSight Console
• Work out difference
– HA or DR
Fail-over CORR
Manager database
17 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Options?
Hardware
• Power
• Disk
• Network
Software
• HA/fail-over/cluster software
Operating system
• HA/fail-over/cluster software
Virtualization
• Don’t forget what you can get here
• Usually a cost option
18 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Summary
Lots of options
• Consider what is needed and how to address
HA deployed at a lot of customers
• Using in-built and external technologies
19 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Please give me your feedback
Session TT3058 Speaker Paul Brettle
20 © Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Thank you
© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.