Scrutinizer Documentation Version 18.6
Total Page:16
File Type:pdf, Size:1020Kb
Scrutinizer Documentation Version 18.6 Plixer Scrutinizer 1 Admin 3 1.1 Admin Tab Overview...................................3 1.2 Data Aggregation...................................... 15 1.3 Interface Details...................................... 19 1.4 Licensing.......................................... 21 1.5 Report Designer...................................... 22 1.6 Reporting.......................................... 24 1.7 User Name Reporting Overview.............................. 25 1.8 User Name Reporting - Active Directory Integration................... 26 1.9 User Name Reporting - Cisco ISE Integration....................... 41 2 Alarms 45 2.1 Overview.......................................... 45 2.2 Gear Menu......................................... 47 2.3 Configuration Menu.................................... 47 2.4 Views Menu........................................ 49 2.5 Bulletin Board Events................................... 52 2.6 Reports Menu....................................... 53 2.7 Edit Policy......................................... 54 2.8 Notification Profile..................................... 56 2.9 Threat Index........................................ 59 3 Baselining 61 3.1 Baselining Overview.................................... 61 4 Dashboards 67 i 4.1 Dashboard Overview.................................... 67 4.2 Vitals Dashboard...................................... 71 5 Flow Analytics 75 5.1 Overview.......................................... 75 5.2 Navigation......................................... 76 5.3 Configuration........................................ 77 5.4 Exclusions......................................... 78 5.5 Algorithm Activation Strategy............................... 80 5.6 Algorithms and Gadgets.................................. 81 5.7 Custom Algorithms.................................... 94 5.8 FA Bulletin Boards..................................... 98 5.9 Optimizing FA....................................... 100 6 Maps 101 6.1 Main View......................................... 101 6.2 Connections........................................ 102 6.3 Dependencies........................................ 103 6.4 Google Maps........................................ 104 6.5 Groups........................................... 105 6.6 Objects........................................... 106 6.7 Plixer Maps......................................... 107 6.8 Settings........................................... 111 7 Status 113 7.1 Status Tab......................................... 113 7.2 CrossCheck......................................... 119 7.3 CSV Reporting....................................... 121 7.4 Device Overview...................................... 121 7.5 Flow Hopper........................................ 122 7.6 Flow View......................................... 122 7.7 Network Traffic Reporting................................. 126 7.8 Report Thresholds..................................... 136 7.9 Run Report......................................... 138 7.10 Scheduling a report..................................... 140 7.11 Vitals Reporting...................................... 143 8 System 147 8.1 Backups.......................................... 147 8.2 Changelog......................................... 148 8.3 Check Vulnerabilities................................... 156 8.4 Distributed Collectors................................... 157 8.5 Flowalyzer......................................... 157 8.6 Interactive scrut_util.................................... 158 ii 8.7 Language Translations................................... 178 8.8 Mailinizer Setup...................................... 179 8.9 Meta Data Collection.................................... 180 8.10 Migration Utility...................................... 182 8.11 Multi-Tenancy Module................................... 190 8.12 NetFlow Help....................................... 190 8.13 NetFlow Knights...................................... 190 8.14 Searching.......................................... 191 8.15 Security Updates...................................... 193 8.16 SSL............................................. 195 8.17 System LEDs........................................ 197 8.18 Third Party Licenses.................................... 200 8.19 Troubleshooting...................................... 221 8.20 Vitals............................................ 222 8.21 Web Server Port...................................... 222 9 Implementation Guides 223 9.1 Configuring Amazon Web Services flow streaming.................... 223 9.2 How to Add Resources to a Scrutinizer EC2 Instance................... 228 9.3 Configuring Cisco’s FireSIGHT eStreamer Client..................... 231 9.4 Configuring Endace Probe Integration........................... 238 9.5 Configuring Scrutinizer for Dual/Multi-homing...................... 240 9.6 Creating a Network Map.................................. 243 9.7 Creating Thresholds and Notifications........................... 244 9.8 Elasticsearch / Kibana (ELK) Integration......................... 247 9.9 Scrutinizer for Splunk Application............................. 250 9.10 Third Party Integration................................... 254 9.11 Using the Reporting API.................................. 261 9.12 Using the IP Groups API.................................. 277 9.13 Using the User API..................................... 284 iii iv Scrutinizer Documentation, Version 18.6 Welcome to the on-line manual. Click Here for online troubleshooting or FAQs. There are also online webcasts which give quick overviews (i.e. 2 - 5 minutes each) of specific features. Important: Don’t struggle, contact Plixer support! Scrutinizer 1 Scrutinizer Documentation, Version 18.6 2 Scrutinizer CHAPTER 1 Admin 1.1 Admin Tab Overview This section covers all the options under Scrutinizer’s Admin Tab. 1.1.1 Settings The Settings page is primarily left to the administrators. • Alarm Notifications: Enable additional system alarms. • Alarm Settings: Modify settings to optimize syslog and SMTP processing. • ASA ACL Descriptions: Enter the username and password used to SSH into ASA firewalls to retrieve ACL descriptions (Appliance only). • AWS Configuration: Set parameters for Amazon Web Services flow streaming configuration here. 3 Scrutinizer Documentation, Version 18.6 • CrossCheck: Specify the thresholds for changing color and the syslog threshold that the Fault Index must reach to trigger a syslog. • Data History: Specify how long each flow interval is saved. – Historical 1 Min Avg: Saves 100% of all flows received. Make sure the server has enough disk space to save significant quantities of the raw flows. The 1 minute intervals consume the most disk space as it is not aggregated and flows are in raw format. – Historical 5 minute - 1 week Avg: These intervals only save the specified Maxi- mum Conversations after aggregation per interval. – Maximum Conversations: Used when creating large intervals (e.g. 5 minute) from prior intervals (e.g. 1 minute). All flows are aggregated together per router. The top 1,000 (default) based on bytes are saved. – Auto History Trimming: This option allows for automatic database trimming when available disk space falls below 10% (with a minimum threshold of 10GB). Check the checkbox to activate this option. An alarm will also be generated to send an alert that the database is being trimmed (1 minute and 5 minute conversa- tion database tables) and includes how much 1 minute and 5 minute data currently exists in the database (in hours). Read more about topics related to this subject: * Data Aggregation * System LEDs Note: In a distributed collector environment, each collector will perform the database trimming independent of the other collectors. Auto History Trimming on/off applies to all of the collectors in the cluster, but the database trimming will only occur on the server(s) that fall below 10% of available disk space. • Email Server: Necessary for on demand and scheduled emailed reports. Make sure the test is successful. • Flow Analytics Configuration: Used to configure the algorithms and monitor their performance. • Flow Analytics Exclusions: Used to manage the Flow Analytics IP Group and hostname exclusions. 4 1. Admin Scrutinizer Documentation, Version 18.6 • Flow Analytics Settings: Used to modify default settings of Flow Analytics relating to FlowPro Defender, jitter, latency, violations and top algorithms. • Licensing: Displays the current licensing level, expiration date(s), and unique Machine ID for this installation. The Machine ID is required by Plixer Customer Service for generating new license keys. Once a new key is received, to activate the key, copy and paste the entire key in the License Key textbox. See the System > Licensing page for more information. • Mapping Groups: Add and manage Map Groups. • Mapping Objects: Add and manage Map Objects. • Proxy Server: Setup the server to work with a proxy server. • Reporting: Report settings configuration options. • Syslog Server: Configure the syslog server, port and priority. • System Preferences: System Preferences are accessible via Admin Tab -> Settings -> System Preferences. The list of options are global configuration settings for all of the collectors. The explanation for each feature is to the right of the setting. 1.1.2 Definitions • 3rd Party Integration: Create links to 3rd party applications and pass variables in URLs. After enabling 3rd Party Integration links will be available in the Device Explorer on the Maps and Status Tabs.