Add an Arc sensor
Before you can use an Arc sensor in Vantage, you must add it.
-
From the section on the right, select Configure Arc
bundle.
A dialog shows.
- Do a check of the defaults settings.
- Select an option:
-
In the Execution time section, enter a value in
seconds.
Note: When this is set to 0, the execution time is interpreted as infinite. -
Enable/disable from these options:
- Sigma rule (Windows only)
- Node points
- Local ARP table
- USB detections (Windows only)
- Smart Polling
-
From the Log level dropdown, select the verbosity level
for the log files. Select from:
- Debug
- Info
- Error
-
If necessary, in the Traffic monitoring section, select
from:
- Enable
- Enable continuous mode
- In the Monitoring time [s] per notification field, enter a value in seconds.
- In the Max packets per notification field, enter a value.
- In the Max used Memory [MB] field, enter a value.
- Select Save.
- In the section on the left, download the applicable package.
- Before you continue, you must configure the sensor.