Log Collection: Remote/Local Collectors Configuration Parameters

Document created by RSA Information Design and Development on Sep 11, 2017Last modified by RSA Information Design and Development on Sep 12, 2018
Version 13Show Document
  • View in full screen mode
 

When you deploy Log Collection, you must configure the Log Collectors to collect the log events from various event sources, and to deliver these events reliably and securely to the Log Decoder host, where the events are parsed and stored for subsequent analysis.

This topic introduces features of the Services Config view > Remote Collectors/Local Collectors tab.

Workflow

This workflow illustrates the basic tasks needed to start collecting events through Log Collection.

workflow - configure collection protocols and event sources

What do you want to do?

                                      
RoleI Want to...Documentation

Administrator

Perform basic Log Collection implementation

Log Collection: Basic Procedure for All ProtocolsBasic Implementation

Administrator

Set up a lockbox to maintain lockbox settings.

Set Up a Lockbox

Administrator

Start Log Collection services.

Log Collection: Start Collection Services and Enable Automatic StartStart Collection Services

Administrator

*Configure Log Collection protocols and event sources.

Configure Collection Protocols and Event Sources

Administrator

Verify that Log Collection is working.

Verify That Log Collection Is Working

*You can perform this task here.

Related Topics

Services Config View

The Services Config view is the view on which you maintain all the Log Collection parameters. The tab in which you maintain the deployment parameters referred to in this guide is the Remote/Local Collectors tab:

  • If you are configuring a Local Collector , NetWitness Platform displays the Remote Collectors tab so that you can configure the Local Collector to pull events from Remote Collectors.
  • If you are configuring a Remote Collector , NetWitness Platform displays the Local Collectors tab so that you can configure the Remote Collector to push events to a Local Collector .

Remote Collectors Tab

On a Local Collector, the Remote Collectors panel provides a way to add or delete Remote Collectors from which the Local Collector pulls events.

                                       
ColumnDescription
add icon Displays the Add Source dialog in which you select the Remote Collectors from which you want the Local Collector to pull events.
delete icon Deletes the Remote Collector from the Local Collector Remote Collectors panel.
edit icon Displays the Edit Source dialog for the selected Remote Collector .
select icon Selects Remote Collectors.
NameNames of the Remote Collectors from which the Local Collector currently pulls events.
AddressIP Addresses of the Remote Collectors from which the Local Collector currently pulls events.
Collections

Choose which collection protocols that the Remote Collector pushes to a Local Collector.

You can select any combination of protocols. If you do not select a protocol, NetWitness Platform selects all protocols.

Local Collector Tab

On a Remote Collector , the Local Collector panel provides a way to add or delete the Local Collectors to which you want to the Remote Collector to push events.

Select the Destination or Source in the Select Configuration drop-down menu.

  • Destination displays the Add Remote Destination dialog.
  • Source displays the Add Source dialog.

The following table describes the Add Source dialog.

                                   
ColumnDescription
add icon Displays the Add Source dialog in which you select the Remote Collectors from which you want the Local Collector to pull events.
delete icon Deletes the Remote Collector from theLocal Collector Remote Collectors panel.
edit icon Displays the Edit Source dialog for the selected Remote Collector .
select icon Selects Remote Collectors.
NameNames of the Remote Collectors from which the Local Collector currently pulls events.
AddressIP Addresses of the Remote Collectors from which the Local Collector currently pulls events.

The following table describes the Local Collectors Panel.

                                       
ColumnDescription
add icon Displays the Add Remote Destination dialog for the Group that you selected. You add destination Local Collectors for this group to which you want the Remote Collector to push events.
delete icon Deletes the destination Log Collector from the group.
edit icon Displays the Edit Remote Destination dialog for the selected destination Local Collector .
select icon Selects a destination Local Collector .
Destination NameDisplays the name of the destination Local Collector .
AddressDisplays the IP address of the destination Local Collector .
Collections

Choose which collection protocols that the Local Collector pulls from a Remote Collector.

You can select any combination of protocols. If you do not select a protocol, NetWitness Platform selects all protocols.

Previous Topic:ODBC DSN Parameters
Next Topic:Tabs
You are here
Table of Contents > Reference > Remote/Local Collectors Configuration Parameters

Attachments

    Outcomes