---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Get started with the HPE ArcSight Logger {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

HPE ArcSight Logger
streams real-time data and categorizes them into specific logs and easily integrates with
Security Operations. Before you
can use the HPE ArcSight Logger
- Incident Enrichment integration, you must download it from the ServiceNow Store and add API URL and
login credentials.

## Before you begin

Role required: sn_si_admin

## Procedure

1. [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. When the installation is complete, navigate to Security OperationsIntegrationsIntegration Configurations.  
   The available security integrations appear as a series of cards. {#activate-configure-arcsight-inc-enrich__Nav-To}
{#activate-configure-arcsight-inc-enrich__Nav-To}
3. In the HPE ArcSight Logger - Incident Enrichment card, select New.
4. Fill in the fields, as needed.  
   {#activate-configure-arcsight-inc-enrich__table_l2p_dcs_ns__entry__2}

   | Field | Description |
   |-|-|
   | Name | The name of this configuration. |
   | ArcSight Logger API Base URL | The base URL you acquired from the HPE Security ArcSight Logger site. |
   | Link URL | \[Optional\] The Link URL that links to an HPE Security ArcSight Logger instance, when available. |
   | Username | Your Intel HPE ArcSight Logger username. |
   | Password | Your Intel HPE ArcSight Logger password. |
   | Earliest Result (days) | The earliest results you want to see in number of days. |
   | Max Rows | The maximum number of rows you want to search. |
   | All Peers | The default is unchecked and searches only the local logger you are connected to. When checked, it searches all the loggers that are connected to one another. |
   | Include raw data samples in search results | Select this to include samples of raw data in your sightings search results. The amount of data returned depends on your setting in the number of rows of raw data property in [Security Incident Response properties](https://servicenow-prod.fluidtopics.net/Ggj2k2A3Ycyj_BpBcgz1tA "Several types of components are installed when you download and activate the Security Incident Response application, including plugin dependencies, user roles, tables, properties, and scheduled jobs."). |
   | MID Server | Select Any to use any active MID Server, or select a specific MID Server name. |
   [ ]

   {#activate-configure-arcsight-inc-enrich__table_l2p_dcs_ns}  
   Note:  
   Configuring this integration activates workflows. To manage the workflows, navigate to the Workflow Editor.
5. Select Submit.  
   The integration configuration card displays.
6. When viewing the new configuration card, you can select Configure or Delete to change or delete the configuration, respectively.
7. To return to the original list of integration configuration cards, select No from the Show Configurations drop-down list.
{#activate-configure-arcsight-inc-enrich__steps_gfz_1yn_vw}

*[\>]: and then


