> For the complete documentation index, see [llms.txt](https://docs.apica.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.apica.io/flow/list-of-forwarders/arc-sight.md).

# ArcSight

ArcSight is a security management tool designed to track and analyze data insights and it ensures compliance with policy guidelines. It provides organizations with the real-time security information that can be used to detect and respond to threats quickly and effectively.

Apica helps you to forward logs to the arc sight using the forwarder plugin.

### Supported Forwarding Formats <a href="#supported-forwarding-formats" id="supported-forwarding-formats"></a>

Apica enables users to quickly and easily forward logs in various formats to security tools, simplifying processing and analysis. The supported formats are,

* Syslog CEF
* ArcSight CEF

### Steps to Create Arc Sight Forwarding <a href="#steps-to-create-arc-sight-forwarding" id="steps-to-create-arc-sight-forwarding"></a>

* Expand the `Create` menu from the navigation bar and click `Forwarder`
* Select the `ArcSight` based on the type of format you want to use
* Click `New Forwarder` button at the top right corner
* Provide the host of the ArcSight and the name of the forwarder
* Click `Create`

Once the forwarder is associated with a specific namespace/application or with various log attributes, the logs that match these criteria will be sent to ArcSight for further analysis.

<figure><img src="https://2948796384-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LmzGprckLqwd5v6bs6m%2Fuploads%2F5invmDX5D2YVScivuH8i%2Fimage.png?alt=media&amp;token=8ef53dee-8d2f-4912-b417-8bc2b8db782c" alt=""><figcaption><p>creating arc sight forwarder</p></figcaption></figure>
