Configure HPE Security ArcSight ESM - Email Parser integration
HPE Security ArcSight ESM - Email Parser integration uses email notifications from ESM to drive enrichment, and response workflows.
Before you begin
Role required: sn_si_admin
About this task
An HPE Security ArcSight ESM - Email Parser template is provided to use for the integration. It must be configured and activated before the integration takes place. Updating the parser activates it.
Procedure
Navigate to All > Security Operations > Integrations > Integration Configurations.
The available security integrations appear as a series of cards.
In the HPE Security ArcSight ESM - Email Parser card, select Configure.
In the HPE Security ArcSight ESM - Email Parser Configuration dialog box, select the Configure Email Parser link.
Select the ArcSight ESM link to edit the settings in the template email parser provided.
At a minimum, fill in the
Email is fromfield. To create you own email parser, see Create email parsers in Security Operations.Check the Active box.
Select Update in the Email Parser form.
The email parser is active. You do not need to return to Integration Configurations.