Create a schedule for ArcSight ESM event ingestion ingestion
You can define the polling or pull schedule for new correlated events. During this step, you can verify the existing settings for correlation event retrieval or modify the scheduling as needed. This step also permits you to retrieve historical correlation events using a date range.
始める前に
Role required: sn_si.admin.
このタスクについて
You can choose whether you want to ingest any historical correlation events during the Scheduling step. You also choose how often you will poll for future new correlation events that match the profile configuration.
As a user with the sn_si.admin role, you configure these polling intervals on a per-profile basis. The performance of the ArcSight ESM correlation event ingestion integration may be impacted by the different polling intervals. When scheduling, you may prefer to balance reducing polling overhead on the ArcSight ESM server against a desire to be notified as soon as possible when an event is created or updated. A five-minute default value is set for any profile, but you may prefer to modify this setting to as low as one minute if required.
Pulling new and updated correlation events