Arcsight Platform 24.2.2 Release Notes
Arcsight Platform 24.2.2 Release Notes
Legal Notices
Open Text Corporation
275 Frank Tompa Drive, Waterloo, Ontario, Canada, N2L 0A1
Copyright Notice
Copyright 2001 - 2024 Open Text.
The only warranties for products and services of Open Text and its affiliates and licensors (“Open Text”) are as may be
set forth in the express warranty statements accompanying such products and services. Nothing herein should be
construed as constituting an additional warranty. Open Text shall not be liable for technical or editorial errors or
omissions contained herein. The information contained herein is subject to change without notice.
Trademark Notices
“OpenText” and other Open Text trademarks and service marks are the property of Open Text or its affiliates. All other
trademarks or service marks are the property of their respective owners.
Contents
What's New 9
Security Updates 9
End of Support Announcements 9
ArcSight Dashboard and Widget SDK 9
Collectors and Connectors in Transformation Hub (CTH) 10
Technical Requirements 11
Downloading the Installation Files for 24.2.2 11
Downloading and Verifying the Installation Files 11
Installing the 24.2.2 Patch 12
Upgrading the Database to 24.2.2 as a Root User 13
Upgrading the Database to 24.2.2 as a Non-root User 14
Upgrading the Database to 24.2.2 on ArcSight Recon R8000 and R8100
Appliances 15
Known Issues 15
Known Issues Related to ArcMC 16
16
736019 — Selecting a value for ArcMC Container Memory Limit Returns an
unformatted screen error 16
698065 — On Azure, Intermittent Login Errors 17
648050 — Routing Rules Character Limitations 17
612094 — Fusion ArcMC Throws 503 Error After Restoring Configuration
Data (AWS, Azure and On-premises) 17
425040 — In Deployment/Topology View, Logger or ESM Destination for
TH Shows Unknown IP Address 18
408195 — Importing a Host File on Fusion ArcMC Points to a Different Log
Folder 18
408194 — Fusion ArcMC Session License Expiration 18
363022 — On G10 Appliance, Gateway Not Correctly Configured After
Restore 18
363017 — On G10 Appliance, IP Address Not Correctly Configured After
Restore 18
359190 — On G10 Appliance, ArcMC Does Not Validate IP Addresses for
NIC Ports 19
773027 — Restored Ability to Specify Time Ranges for Custom Reports and
Dashboards Because the Enter Parameters Modal is not Displayed 46
566085 — Network Chart Data are No Longer Presented in Portions and
Cut 46
Resolved Issues Related to Search 46
733209 — Scheduled Searches no Longer Display an Error When You Try to
Load a Field Summary on a Completed Run 46
616090 — For System Search Queries, #SSH Authentication No Longer
Generates an Error 47
608098 — Certain top/bottom Queries and Fields that Begin With "Device"
no Longer Fail 47
Resolved Issues Related to SOAR 47
591118 - Enrichment History - Sort By Capability And Status Functionality
Does not Sort By Alphabetical Order 48
655004 - SOAR FortiAnalyzer Plugin Should Accept Dynamic Ports 48
724037 - Enhancement - SOAR Should Support Updating User's Email
Address and Username When Changed in FUM 48
719017 - Proxy Option Missing in SMTP Mail Server Integration
Configuration 48
737015 - API Documentation soar-api/js-api-doc Search Does Not Work 49
8502032 - ''Access Denied'' Error During Action Rollback with Manage
SOAR Integrations Permission 49
853043 - SOAR Response Headers Returning Only One Header Key Value
Even When Multiple Keys Are Present 49
853078 - EWS Mail Receiver Should Get All Body Content 49
854004 - Case and Alerts Details Missing in Email Notification 49
857027 - Access is Denied when Creating a Search in SOAR cases including
Alert Source Rule Name Condition 49
866085 - CreateTicketComment Method Does Not Work Properly 49
877024 - Missing Job ID Scope Item in EnCase Plugin 49
880090 - SOAR Performance Issue Due to Lack of Index for Ticket Table 50
190609 - Missing Type Parameter in Scope Action Parameter 50
Resolved Issues Related to Transformation Hub 50
Contacting OpenText 51
Additional Documentation 51
Publication Status 52
Component Version
Note: ESM CE 24.3 (7.8) is not supported with any of the released ArcSight Platform
versions up to and including version 24.2.2. For information about disabling ESM in the
ArcSight Platform, see the Administrator's Guide for the ArcSight Platform that
corresponds to your deployment type: Off-Cloud, Azure, AWS, or GCP.
After you disable ESM, the related menus will be visible but will not work. To remove the
menus, clear the cache and then log in again.
The documentation for this product is available on the ArcSight documentation website in
HTML and PDF formats. If you have suggestions for documentation improvements, click
comment or support on this topic at the bottom of any page in the HTML version of the
documentation posted on the ArcSight Platform CE Documentation page or the
documentation pages for the included products.
What's New
Security Updates
This release of the ArcSight Platform addresses and resolves CVE BZ-1174867 and CVE-2024-
9841 (Reflected Cross-Site Scripting).
Technical Requirements
For more information about the software and hardware requirements required for a successful
deployment, see the Technical Requirements for ArcSight Platform. These Technical
Requirements include guidance for the size of your environment based on expected workload.
OpenText recommends the tested platforms listed in this document.
Customers running on platforms not provided in the Technical Requirements or with untested
configurations will be supported until the point OpenText determines the root cause is the
untested platform or configuration. According to the standard defect- handling policies,
OpenText will prioritize and fix issues we can reproduce on the tested platforms.
3. Download all four of the necessary product installer files (listed above) from the OpenText
Downloads website along with their associated signature files (*.sig).
Evolving security needs imply the renewal of certificates for the signature verification
procedure. To ensure a successful verification of your product signature, download the
latest public keys file before proceeding with the verification process (step 1 of the Get the
Public Keys procedure).
OpenText provides a digital public key that is used to verify that the software you
downloaded from the OpenText software entitlement site is indeed from OpenText and
has not been tampered with by a third party. For more information and instructions on
validating the downloaded software, visit the OpenText Code Signing site. If you discover a
file does not match its corresponding signature (.sig), attempt the download again in case
there was a file transfer error. If the problem persists, please contact OpenText Customer
Support.
cd /tmp/arcsight_db_patch
/tmp/arcsight_db_patch/db_upgrade -c upgrade-utilities
/opt/arcsight-db-tools/scripts/watchdog.sh disable
/opt/arcsight-db-tools/db_installer stop-db
/tmp/arcsight_db_patch/db_upgrade -c upgrade-db-rpm
/opt/arcsight-db-tools/kafka_scheduler start
/opt/arcsight-db-tools/scripts/watchdog.sh enable
For information about using the ArcSight Platform Installer, see Using ArcSight Platform
Installer to Deploy Off-cloud as a Root User in the Administrator's Guide for ArcSight Platform
24.2.
2. After the line "Cmnd_Alias ARCSIGHT = \", add sudoers settings listed below.
/opt/vertica/sbin/update_vertica, \
/usr/bin/id dbadmin, \
/bin/[ -e /opt/vertica/data/ ], \
/bin/[ -e /usr/bin/sudo ], \
/bin/[ -f /etc/redhat-release ], \
/bin/[ -e *dbadmin/ ], \
sudo su -
3. Perform steps 2 through 8, described in the “Upgrading the Database to 24.2.2 as a Root
User” section above.
Known Issues
These issues apply to common or several components in your ArcSight Platform deployment.
For more information about issues related to a specific product, please see that product's
release notes.
OpenText strives to ensure that our products provide quality solutions for your enterprise
software needs. If you need assistance with any issue, visit OpenText Support, and then select
the appropriate product category.
All issues listed in this section belong to the OCTCR33I repository, unless otherwise noted.
Upgrading the Database to 24.2.2 on ArcSight Recon R8000 and R8100 Page 15 of 52
ArcSight Platform CE Release Notes
The output of the command should show a value of 4/4 (the pod's READY state) and of
Running (the pod's STATUS) for the fusion-arcmc-web-app pod.
3. Go to the ITOM Management portal and click on the 3 dots menu. Select the Reconfigure
option.
4. Go to ArcMC Configuration and select a value for ArcMC Container Memory Limit (4GB,
5GB, 6GB, 7GB or 8GB).
5. Click the Save button.
cd /mnt/efs/<nfs_folder>/
$ kubectl delete pods -n $(kubectl get namespaces | grep arcsight | cut -d '
' -f1) $(kubectl get pods -n $(kubectl get namespaces | grep arcsight | cut
-d ' ' -f1) | grep arcmc | cut -d ' ' -f1)
Workaround: From the CLI, modify the IP address with the correct information. For reference,
consult the ArcMC Admin Guide, section: "Configure a New IP Address".
359190 — On G10 Appliance, ArcMC Does Not Validate IP Addresses for Page 19 of 52
ArcSight Platform CE Release Notes
As a result, analytics is unable to load the other data sources, such as Resource, Share, VPN,
and Repository.
Workaround: Perform the following steps to specify each data source for the data source
configuration:
1. Open a certified web browser.
2. Specify the following URL to log in to the OMT Management Portal: https://<omt_
masternode_hostname_or_virtual_ip_hostname>:5443.
3. Select Deployment > Deployments.
4. Click ... (Browse) on the far right and choose Reconfigure. A new screen will be opened in a
separate tab.
5. Click Intelligence.
6. In the Analytics Configuration - Database section, modify Database Loader Data Sources
field's value to ad,pxy,res,sh,vpn,repo.
729040 — SearchManager Pods Fail Due to the Absence of Spacing in the Page 21 of 52
ArcSight Platform CE Release Notes
8. Click Update.
9. Restart the interset-api pods:
616036 — If Not Already Logged into Fusion, the First Attempt to Log Directly Page 22 of 52
ArcSight Platform CE Release Notes
8. Click Update.
9. Restart the interset-api pods:
a. Launch a terminal session and log in to the master or worker node.
b. Execute the following command to retrieve the namespace:
399297 - Intelligence Search API Fails with a Timeout Error (esSocketTimeout Page 23 of 52
ArcSight Platform CE Release Notes
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
scale statefulset interset-logstash --replicas=0
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
edit configmaps logstash-config-pipeline
401549 - Most Pods Enter into the CrashLoopBackOff State if the KeyStore Page 24 of 52
ArcSight Platform CE Release Notes
kubectl -n $(kubectl get namespaces | grep arcsight | cut -d ' ' -f1)
scale statefulset interset-logstash --replicas=<number_of_replicas>
613050 - Installer Does Not Validate the Value You Specify for
Elasticsearch Data Retention Period
Issue: In the OMT Management Portal > Configure/Deploy page > Intelligence > Elasticsearch
Configuration section, the installer does not validate the value you specify for the Elasticsearch
Data Retention Period field. The tool-tip for the Elasticsearch Data Retention Period field
suggests that you should specify a value greater than 30 for indices retention. However, there
is no validation preventing you from entering a value that is less than 30. If you specify a value
that is less than 30, the value for Elasticsearch Data Retention Period will be set to the
minimum default value of 30 days.
Workaround: There is no workaround at this time.
613050 - Installer Does Not Validate the Value You Specify for Elasticsearch Page 26 of 52
ArcSight Platform CE Release Notes
Workaround: You must restart the Elasticsearch cluster to refresh the Elasticsearch
environment.
Workaround: If this issue occurs, you should set up an SSH connection between the Logger and
the database. This workaround applies to an off-cloud deployment of the ArcSight Database on
a server running RHEL 9.2 as well as on an appliance for ArcSight Recon.
1. Log in to the database server:
l For an off-cloud deployment: Log in to the primary ArcSight Database node as a root
user.
l For a Recon appliance: Log in as an ArcSight user.
2. If your login credentials do not have the database administrator permissions, change to a
database admin user:
l For an off-cloud deployment: su - [dbadmin_username]
l For a Recon appliance: sudo su - [dbadmin_username]
3. To set up a SSH connection with the Logger, enter the following command:
Workaround:
<OMT_HOME>/bin/kube-restart.sh
For example:
/opt/arcsight/kubernetes/bin/kube-restart.sh
firewall-cmd --add-forward
firewall-cmd --add-forward --permanent
firewall-cmd --add-interface cni0
firewall-cmd --add-interface cni0 --permanent
These steps are included into the arcsight-install --cmd upgrade command, so they're not
necessary with arcsight-install upgrades.
844085 — An Operation to Add a New Role or Group to a User Succeeds, But Page 30 of 52
ArcSight Platform CE Release Notes
.. <> ...
3. List the relations to see the flag, remove it and exit the psql with "\q" and ssh pod with
"exit"
4. Restart the autopass pod using kubectl delete pod, and then make sure the container
l "336023 — Operations Performed on an Open Admin Tab Do Not Complete After You Log
Out From Another Capability (Recon or Reporting) Tab" on the next page
l "331194 — Reports and Dashboards Use UTC Time Zone" on the next page
l "186007 — An Exported Report Might Have Format Issues" on the next page
l "162054 — Warning Message is Displayed: Query Plan Prevents Materialized View (MV)
Sharing" on the next page
Workaround: Refresh the page to load the Contract & Usage page.
837049 — Delete Scheduled Search Dialog Box is Missing the OpenText Page 36 of 52
ArcSight Platform CE Release Notes
766026 — User Preferences Drop-down Menus are Closed if You Click in the Page 37 of 52
ArcSight Platform CE Release Notes
Workaround: Post-migration, create a new search that uses the same settings.
113040 — CSV File Export Fails after You Change the Date and
Time Format
Issue: After modifying the date and time format in preferences, the CSV export function for
saved searches runs before the preference change fails.
Workaround: Run the scheduled search again, then save it. Select the CSV icon to download
the file
The result is that destination topics for affected CEF rules may not receive intended events, or
may receive unintended events.
If the output shows all instances are running on the same worker node, Schema Registry must
be restarted to spread the instances across worker nodes.
2. Restart Schema Registry.
Verify restart has completed by waiting until all Schema Registry pods have a status of Running,
and a small age value of the minutes or seconds since you performed the restart.
After the restart completes, verify the instances are now running on different worker nodes.
409228 — Schema Registry Instances May Be Allocated to Single Worker Node Page 41 of 52
ArcSight Platform CE Release Notes
In a multi-node scenario, a topic used internally by Schema Registry may get configured with
too few replicas, which reduces reliability and can make the registry fail during failover. Check
the topic's configuration to verify it has the proper replica count (replication factor).
3. In a multi-node deployment, identify the replica count for the topic "_schemas". Set the
topic to be used in later commands.
topic="_schemas"
5. If the replication factor is not 3, perform the following steps to change the
configuration: Get the list of brokers to set as replicas, including the topic's partition
leader. If the cluster has more than three brokers, limit the replicas to three.
topicfile=/tmp/topic.json
assignfile=/tmp/assign.json
printf '{"topics": [{"topic": "%s"}], "version":1}' $topic > $topicfile
kubectl cp $topicfile $namespace/th-kafka-0:$topicfile
kubectl -n $namespace exec th-kafka-0 -- kafka-reassign-partitions --broker-
list "$allbrokerids" --bootstrap-server th-kafka-svc:9092 --generate --
topics-to-move-json-file $topicfile > $assignfile
sed -i '1,/Proposed partition reassignment/d' $assignfile
sed -i -r "s/(,.replicas.:\[)([0-9,]+)/\1$blist/" $assignfile
sed -i 's/,\s*"log_dirs"\s*:\s*[[][^]]*[]]//' $assignfile
kubectl cp $assignfile $namespace/th-kafka-0:$assignfile
rm -f "$assignfile" "$topicfile"
409228 — Schema Registry Instances May Be Allocated to Single Worker Node Page 42 of 52
ArcSight Platform CE Release Notes
8. Verify the reassignment completes by running a verify command with the same input file.
9. Since the replicas have changed, run a preferred leader election for the topic's partition.
electfile=/tmp/election.json
printf '{"partitions": [{"topic": "%s","partition":0}]}\n' $topic >
$electfile
kubectl cp $electfile $namespace/th-kafka-0:$electfile
rm -f "$electfile"
kubectl exec -n $namespace th-kafka-0 -- kafka-leader-election --bootstrap-
server th-kafka-svc:9092 --election-type preferred --path-to-json-file
$electfile
Also in a multi-node scenario, an internal ArcSight topic may get configured with too few
replicas, which reduces reliability of Stream Processor metrics and can prevent ArcMC from
displaying the metrics. Check the topic's configuration to verify it has the proper replica count.
In a multi-node deployment, identify the replication factor for the topic "th-arcsight-avro-sp_
metrics".
10. Set the topic to be used in later commands.
topic=th-arcsight-avro-sp_metrics
Repeat all of steps 4 and 5 above to check the topic and modify it if needed. The topic needs to
have the same replica count as the previous topic: three.
409228 — Schema Registry Instances May Be Allocated to Single Worker Node Page 43 of 52
ArcSight Platform CE Release Notes
Resolved Issues
These issues apply to common or several components in your ArcSight Platform deploy. For
more information about issues related to a specific product, please see that product's release
notes, as applicable.
All issues listed in this section belong to the OCTCR33I repository, unless otherwise noted.
As a result, analytics is unable to load the other data sources, such as Resources, Share, VPN,
and Repository.
Fix: This issue has been resolved now.
l "566085 — Network Chart Data are No Longer Presented in Portions and Cut" on the next
page
779004 — VPM Conditions/Triggers are now Being Applied for Scheduled Page 46 of 52
ArcSight Platform CE Release Notes
733209 — Scheduled Searches no Longer Display an Error When You Try to Page 47 of 52
ArcSight Platform CE Release Notes
724037 - Enhancement - SOAR Should Support Updating User's Email Address Page 49 of 52
ArcSight Platform CE Release Notes
Contacting OpenText
For specific product issues, contact OpenText Support.
Additional technical information or advice is available from several sources:
l Product documentation, Knowledge Base articles, and videos.
l The OpenText Community pages.
Additional Documentation
The ArcSight Platform documentation library includes the following resources:
l Administrator's Guide for ArcSight Platform, which contains installation, user, and
deployment guidance for the ArcSight software products and components that you deploy
in the containerized platform.
See the guide that corresponds to your deployment:
o Administrator's Guide for the ArcSight Platform 24.2 - AWS Deployment
o Administrator's Guide for the ArcSight Platform 24.2 - Azure Deployment
o Administrator's Guide for the ArcSight Platform 24.2 - Google Cloud Deployment
o Administrator's Guide for the ArcSight Platform 24.2- Off-Cloud Deployment
l Technical Requirements for ArcSight Platform, which provides information about the
hardware and software requirements and tuning guidelines for the ArcSight Platform and
the deployed capabilities.
l User’s Guide for ArcSight Platform, which is embedded in the product to provide both
context-sensitive Help and conceptual information.
l Product Support Lifecycle Policy, which provides information on product support policies.
Publication Status
Released:Tuesday, November 5, 2024
Updated: Tuesday, November 5, 2024