Integrate Platform and SOAR to existing SIEM

Hello,
currently I have software version of Logger,ArcMC and ESM on separated servers. If I want to use SOAR and other Arcsight Platform products can I just setup 4th server with CDF and then use for example this config 

"example-install-config-recon-single-node.yaml" to install Recon and SOAR and connect it to the existing Logger and ESM ?

Regards
Jan

Parents Reply
  • 0 in reply to 

    Hello Maresj, 

    I think that you are referring to this scenario "www.microfocus.com/.../ TocPath=Examples%2520of%2520Deployment%2520Scenarios%257C_____3" right?

    Note: Keep in mind that the above scenario is only with ESM and there is no scenario for Logger to be on the same vm/server with OMT.

    Going back to your question, well, that's depends on what's your goal.

    But what I have seen is that someone who wants to try SOAR sooner or later will want to try the other capabilities. If you have ESM and OMT on the same server well that will be harder to expand vs if you already started from the beginning with separate environments, for example allocating one vm/server to ESM and starting with a separate one vm/server for OMT ( even with one capability been deployed).

    Best Regards,

    Daniel

Children
No Data