Before you can deploy RSA NetWitness® Platform in Azure, you need to:
- Understand the requirements of your enterprise.
- Know the scope of a NetWitness Platform deployment.
When you are ready to begin the deployment:
- Make sure that you have a NetWitness Platform "Throughput" license.
- Use Chrome for your browser (Internet Explorer is not supported).
Azure Environment Recommendations
Azure instances have the same functionality as the NetWitness Platform hardware hosts. RSA recommends that you perform the following tasks when you set up your Azure environment.
- Based on the resource requirements of the different components, follow best practices to use the system and dedicated storage appropriately.
- Build Concentrator directory for index database on SSD.
Abbreviations and Other Terminology Used in this Guide
The following diagrams illustrate some common Azure deployment scenarios. In the diagrams, the:
- Log Decoder receives logs collected by the Log Collector. The Log Collector collects log events from hundreds of devices and event sources.
Concentrator indexes metadata extracted from network or log data and makes it available for enterprise-wide querying and real-time analytics while facilitating reporting and alerting.
- UEBA provides comprehensive user and entity behavioral analytics to better detect, investigate, and respond to advanced internal attacks and identity-based anomalies.
- Endpoint Hybrid or Endpoint Log Hybrid is used for collection of endpoint data. The Endpoint Hybrid comprises of an Endpoint Server, Log Decoder, and a Concentrator.
- NetWitness Server hosts Respond, Reporting Engine, Investigate, RSA Live, Administration, Endpoint Hybrid/Log Hybrid and other aspects of the user interface.
Full NetWitness Platform Stack Azure Visibility
This diagram shows all NetWitness Platform components (full stack) deployed in Azure.
Hybrid Deployment - Log Decoder
This diagram shows the Log Decoder and Archiver deployed in Azure with all other NetWitness Platform components deployed on your premises.
RSA provides the following NetWitness Platform services.
- NetWitness Server
- Admin Server
- Config Server
- Investigate Server
- Orchestration Server
- Reporting Engine
- Respond Server
- Security Server
- Event Stream Analysis
- Log Decoder
- Remote Log Collector
- Endpoint Server
The following list the flow for Azure deployment: