Configure HP ArcSight for Integration with Bomgar Privileged Access
If desired, a custom tool can be created within the ArcSight Console to allow users to Jump directly to an endpoint from an event entry. This approach leverages Bomgar PA's Client Scripting API to construct an open URL in your browser of choice to make sure no additional software is required. The URL instructs the Bomgar Appliance to generate and download a Bomgar console script file run by the access console to initiate the Jump session. To create the tool, follow the steps below.
In the ArcSight Console, click Tools > Local Commands > Configure.
Click New to create a new Local Command.
In the Tool settings dialog, configure the tool as follows:
Field Name Field Value Name
Access via Bomgar
Program [Browse to and select the executable (.exe) for your preferred browser] Working Directory [The directory containing the executable for your preferred browser] Icon [Can be the default, tools_custom.gif, or any other image you choose] Program Parameters
Show in toolbar [Checked] Use with data export [Unchecked
- Click OK to create the tool and close the Configure Tools window.
- You can now right-click on any cell in the grid containing an IP address or hostname that matches an existing endpoint in the rep console to initiate a session.
Note: The Bomgar Appliance does not require any additional configuration or changes beyond those mentioned in the Bomgar SIEM Tool Plugin Installation and Administration.