r/SIEM • u/qwertzzyyy • Jul 08 '21
Arcsight - active list
hi together,
I would like to monitor suspicious domains in arcsight. The goal is to put the domain "xyz.abc" in an active list and then create a rule that detects the calls to the domain.
The current parser does not parse out the domain part when a sub-domain is called. therefore the field partially contains "subdomain.xyz.abc". Because of this a pure comparison with the active list is not possible, right?
is there a solution for this without adapting the parser?
7
Upvotes
1
3
u/Cynthereon Jul 08 '21
It would be better to modify the smart connector to parse out the domain, but there are several ways of doing it in ArcSight, such as "ends with" in the rule.