Scrutinizer Documentation Version 19.0.2 Plixer
Total Page:16
File Type:pdf, Size:1020Kb
Scrutinizer Documentation Version 19.0.2 Plixer May 26, 2021 Contents 1 Deployment guides1 1.1 Virtual Appliance deployment guide............................1 1.2 AMI deployment guide................................... 32 2 System administration 39 2.1 Changelog......................................... 39 2.2 Checking for vulnerabilities................................ 53 2.3 Data aggregation...................................... 54 2.4 Support for distributed collectors............................. 58 2.5 Functional IDs....................................... 59 2.6 Interactive CLI....................................... 61 2.7 Language translations................................... 83 2.8 Licensing.......................................... 84 2.9 Predicting disk needs.................................... 85 2.10 Replicator load balancing................................. 86 2.11 Security updates...................................... 87 2.12 Sharing meta data with Plixer............................... 88 2.13 Sizing your environment.................................. 90 2.14 SSL configuration..................................... 95 2.15 Streaming support for customer data lakes........................ 98 2.16 Third-party licenses.................................... 98 2.17 Upgrade guide....................................... 119 3 Integration guides 121 3.1 Advanced Threat Intelligence Feed............................ 121 3.2 Amazon Web Services flow logs.............................. 122 i 3.3 Elasticsearch / Kibana (ELK) integration......................... 126 3.4 Endace probe integration.................................. 130 3.5 Cisco’s FireSIGHT eStreamer client............................ 131 3.6 Grafana integration..................................... 137 3.7 Plixer Beacon........................................ 145 3.8 Plixer Replicator load balancing.............................. 146 3.9 SD-WAN integrations................................... 148 3.10 ServiceNow bi-directional integration........................... 150 3.11 Scrutinizer for Splunk application............................. 150 3.12 STIX-TAXII feeds..................................... 154 3.13 Third-party integrations.................................. 155 3.14 User name reporting - Active Directory integration.................... 161 3.15 User name reporting - Cisco ISE integration........................ 176 4 Flow Analytics 179 4.1 Overview.......................................... 179 4.2 Algorithms and gadgets.................................. 181 4.3 Algorithm activation strategy............................... 196 4.4 Threat Index........................................ 198 4.5 Configuration........................................ 199 4.6 Custom algorithms..................................... 201 4.7 FA Bulletin Boards..................................... 205 4.8 Baselining......................................... 207 5 Scrutinizer API 213 5.1 IP Groups API....................................... 213 5.2 Reporting API....................................... 223 5.3 User API.......................................... 231 6 Machine learning 247 6.1 ML Engine AMI deployment guide............................ 247 6.2 ML Engine Virtual Appliance deployment guide..................... 248 6.3 Forecasting with Plixer Network Intelligence....................... 249 7 User interface 253 7.1 Overview.......................................... 253 7.2 Admin........................................... 255 ii CHAPTER 1 Deployment guides 1.1 Virtual Appliance deployment guide 1.1.1 What you need to know about deploying a Plixer Scrutinizer Virtual Appliance The Plixer Scrutinizer Virtual Appliance can be obtained from Plixer or your local reseller. It is down- loaded as an all-in-one virtual appliance which can be deployed on an ESXi v5.5 and above or Hyper-V 2012 hypervisor. • You will need to obtain an appliance license or evaluation license from Plixer or your local reseller in order for the Plixer Scrutinizer Virtual Appliance to function properly. • It is recommended to give the Plixer Scrutinizer virtual machine NIC a static MAC address to pre- vent the machine ID from changing. This is especially important in clustered virtual environments where the VM can change hosts and MAC addresses. If the MAC address changes, the VM will need a new license key. 1 Scrutinizer Documentation, Version 19.0.2 • The Plixer Scrutinizer Virtual Appliance is deployed on a hypervisor server. It will use 100GB of disk space, 16GB of RAM, and 1 CPU with 4 cores. • The performance you get out of a Plixer Scrutinizer Virtual Appliance will be directly dependent on the hardware on which it’s deployed. It’s recommended to dedicate, not share, all the resources that are allocated to the Plixer Scrutinizer virtual machine. This is especially important for the Plixer Scrutinizer datastores. In environments with high volumes of NetFlow data, Plixer Scrutinizer will require dedicated datastores which are discussed in further detail later in this document. Plixer Scrutinizer hardware appliances are recommended for deployments of exceedingly high volume of flow as they are designed to handle the highest flow rates. • With the default of 100GB of disk space, you can store up to 1 month of NetFlow v5 data from 25 devices at 1,500 flows a second. If you’re planning on exceeding this volume of flow data, or if you need to store data for longer than 30 days, there are detailed steps indicated below that will show you how to expand the amount of disk space allocated to the appliance. • To enable the ability to shut down the Plixer Scrutinizer Virtual Appliance through vSphere, install VMware Tools using the instructions in this document. Using the “Power -> Off” method will result in database corruption. 1.1.2 System requirements The Plixer Scrutinizer Virtual Appliance has the following requirements: Component Minimum Specifications (for trial Recommended Specifications (for produc- installations) tion environments) RAM 16GB 64GB Disks 100GB 1+ TB 15K RAID 0 or 10 configuration Processor 1 CPU 4 cores 2GHz+ 2 CPUs 8 Cores 2GHz+ Operating ESXi 5.5+, Hyper-V 2012, KVM 14 ESXi 6+, Hyper-V 2012, KVM 16 System 1.1.3 Plixer Scrutinizer OVF deployment on ESX 1. Download the latest Plixer Scrutinizer Virtual Appliance 2. Using VMware vSphere, or vCenter, connect to the ESX host where you will deploy the appliance 2 1. Deployment guides Scrutinizer Documentation, Version 19.0.2 3. Right-click a host you wuld like to deploy the appliance on. Choose the Deploy OVF Template menu option. 4. Select “Local file” and browse to the downloaded Plixer Scrutinizer OVF file and the Plixer Scruti- nizer VMDK file, then click “Next”. 5. Give your Plixer Scrutinizer VA a name and press “Next”. 6. Select an ESX to deploy the machine on if your host is not already selected and press “Next”. 7. Review the details of the virtual machine and press “Next”. 8. Select your datastore, set your disk format to “Thin Provision” and press “Next”. Note: Be sure to read the Optimizing Plixer Scrutinizer Datastores section to obtain the best performance and collection rates. 9. Select the network to be used by the Plixer Scrutinizer Virtual Appliance. 10. A summary of the options you chose will appear. Click “Finish” and it will import the Plixer Scrutinizer Virtual Appliance. This can take a few moments. 1.1. Virtual Appliance deployment guide 3 Scrutinizer Documentation, Version 19.0.2 11. Before powering on the Plixer Scrutinizer virtual machine, it’s important to set a static MAC address for licensing purposes. Right-click on the Plixer Scrutinizer VM and select “Edit Settings. ” 12. Select the Network adapter, set the MAC Address to Manual, enter in a unique MAC Address, and then proceed to the next step. 4 1. Deployment guides Scrutinizer Documentation, Version 19.0.2 13. The next step is to allocate and dedicate resources to the Plixer Scrutinizer virtual machine. For evaluation purposes, the Plixer Scrutinizer OVF grabs 1 CPU with 4 cores, 16GB of RAM, and 100GB of disk space. When deploying the Plixer Scrutinizer Virtual Appliance it’s recommended to increase the re- sources to meet the recommended system requirements listed earlier in this document. Since all installs will vary, more resources may be required. Start on the “Virtual Hardware” tab and increase the Memory, CPUs, and Hard disk as necessary (see system requirements section for more detail). 1.1. Virtual Appliance deployment guide 5 Scrutinizer Documentation, Version 19.0.2 14. Next, navigate to the “Resources” tab. Under CPU and Memory, set the “Shares” value to High and set the “Reservation” maximum value to the amount of resources dedicated to the virtual machine. Now press “OK”. Note: The amount of RAM in the screenshot below is on a small test ESX server, so it won’t match a production install. 6 1. Deployment guides Scrutinizer Documentation, Version 19.0.2 15. Right-click on the Plixer Scrutinizer virtual machine and power it on. 16. Click the console preview window and select “Open Remote Console”. A new window will open and you can then login to the Plixer Scrutinizer Virtual Appliance using root/scrutinizer. Note: The server will perform a quick setup and immediately reboot. 1.1. Virtual Appliance deployment guide 7 Scrutinizer Documentation, Version 19.0.2 17. Log in to the server again and answer the provided questions. Press “Enter” and the server will reboot to apply the necessary settings. 18. Now log in to the Plixer Scrutinizer web interface in your web browser