McAfee ESM

McAfee Enterprise Security Manager is a security information and event management (SIEM) solution that delivers actionable intelligence and integrations to prioritize, investigate, and respond to threats.

Integration with LogicHub

Connecting with McAfee ESM

To connect to McAfee ESM following details are required:

  • Label: Connection name.
  • Reference Values: Define variables here to templatize integration connections and actions. For example, you can use https://www.{{hostname}}.com where, hostname is a variable defined in this input. For more information on how to add data, see 'Add Data' Input Type for Integrations.
  • Host: Host of the McAfee ESM server.
  • User: User name to log in with.
  • Password: Password to log in with.

Actions with McAfee ESM

Get Events

Fetches events based on query provided.

Inputs to this Action

  • Connections: Choose a connection that you have created.
  • Query: Query that is used for fetching events.
  • Time Range: Set the time frame to check for events.

Check GUI Accessible

Checks whether ESM GUI is accessible.

Inputs to this Action

  • Connections: Choose a connection that you have created.

Status Flags Screenshot

Screenshots Status Flags of ESM Devices.

Inputs to this Action

  • Connections: Choose a connection that you have created.
  • Screenshot Timeout: Amount of time (in seconds) to spend retrieving a screenshot (Default is 40 seconds).

Default View Screenshot

Screenshots Default View on ESM Dashboard.

Inputs to this Action

  • Connections: Choose a connection that you have created.
  • Screenshot Timeout: Amount of time (in seconds) to spend retrieving a screenshot (Default is 40 seconds).

Review ESM Resources

Reviews ESM Resources such as CPU, RAM, and HDD.

Inputs to this Action

  • Connections: Choose a connection that you have created.

Get Alarms

Gets alarms triggered for a time range.

Inputs to this Action

  • Connections: Choose a connection that you have created.
  • Time Range: Set the time frame to check for triggered alarms.

Review ESM Health Status Flags

Reviews anomaly in ESM Health Status Flags.

Inputs to this Action

  • Connections: Choose a connection that you have created.
  • Ignore Disabled Services: Choose option to ignore disabled devices for health check (Default is False).

Review Baselines on ESM

Reviews Event Distribution Widget in Event Summary View with Baselines.

Inputs to this Action

  • Connections: Choose a connection that you have created.
  • Ignore Disabled Services: Choose option to ignore disabled devices for health check (Default is False).
  • Time Range: Set the time frame to get Event Distribution.

Review Tasks Under Task Manager

Reviews tasks/jobs/queries running on ESM listed under Task Manager.

Inputs to this Action

  • Connections: Choose a connection that you have created.

Review Reports

Reviews Reports generated on ESM.

Inputs to this Action

  • Connections: Choose a connection that you have created.

Did this page help you?