GSG-Gen4 Windows Appliance SoftwareConfig Latest
GSG-Gen4 Windows Appliance SoftwareConfig Latest
GSG-Gen4 Windows Appliance SoftwareConfig Latest
IMPORTANT: Please work with your LogRhythm Professional Services Consultant to complete the procedures
outlined in this guide.
Prerequisites
Before starting your configuration, you will need:
• The LogRhythm License file (.LIC), usually provided in an email
• The factory default password for your deployment
3. On the Alarming and Response Manager tab, complete the following fields:
4. Click OK.
3. Click OK.
3. Click OK.
• User ID – logrhythmadmin
3. Click OK.
a. Enter the host name where the Platform Manager is located. This can be found by right-clicking My
Computer and selecting Properties. Click the Computer Name tab and get the Full Computer Name
up to the first period where the domain name will start.
b. If the appliance type is XM, all LogRhythm components are contained in a single appliance.
Note: This file is provided by LogRhythm Support after purchase and shipment of the appliance(s), and it
is required to access and configure LogRhythm.
a. Navigate to the location of the license file (*.lic) by clicking the ellipses at the far right.
b. Locate and select the master license file and click Open. The path and file name are listed in the
License File text box.
c. Click OK.
8. When prompted, select the appropriate Data Processor licensing mode from the available, valid
options. The mode depends on:
a. Software (n available licenses) - Select this option to identify a software only purchase
b. Appliance Mode for software and appliance purchase - Select this option to identify a software
and appliance purchase
c. Data Processor MPS mode for software and appliance purchase - Select this option to use a
Messages Per Second license
9. Click Next.
All dialog boxes close and the main Client Console window is displayed.
1. Deploy the Knowledge Base by selecting one of the three following options:
• I have Internet access and want to automatically download the KB (recommended).
a. Proxy Server Address - Enter the Proxy Server Address for the KB Download
b. Proxy Server Port - Enter the port number for the server
c. Select the Proxy Server Requires Authentication check box
d. Enter the appropriate credentials and Host name, if necessary
e. Click OK. The Knowledge Base is downloaded.
f. Click OK. Proceed to the Knowledge Base Importer Wizard section.
• I do not have Internet access or want to manually download the KB.
The Manual Knowledge Base Download window appears.
ii. Upon completion the message Knowledge Base unpacked appears in the status. Click Next
to import the Knowledge Base.
1. Click OK.
2. In the Platform Manager Properties dialog box, click the browse icon next to the Platform box.
3. In the Platform Selector table, select the row corresponding to your appliance, and then click OK.
5. Click OK.
6. In the Data Processor Properties dialog box, click the browse icon next to the Platform box.
7. In the Platform Selector table, select the row corresponding to your appliance, and then click OK.
9. Click OK.
4. Click OK.
5. Click OK.
2. Click Start.
3. Right-click the selected Data Processor, click Actions, and then click Service Start.
3. Right-click the selected System Monitor, click Actions, and then click Service Start.
The System Monitor Agent is displayed in the top pane and listed as pending.
The “Associate New System Monitor Agent with an Existing Agent” message is displayed.
7. Click OK.
NOTE: You must perform these steps for each Data Indexer (XM or DPX) in your deployment. Ensure that the
LogRhythm DX – AllConf and LogRhythm DX – Configuration Server services are running before
trying to connect to the Data Indexer.
Configure the Data Indexer via the configuration web page hosted on the Data Indexer. Please note the following
requirements:
• On a Windows Data Indexer, you can only access the web page locally or through a remote
desktop/terminal services session to the appliance
• You can only access the web page using Google Chrome, Mozilla Firefox (latest versions of each), or
Internet Explorer 11.
NOTE: Do not attempt to modify any configuration files. If you have any issues, please contact
LogRhythm Support.
To access the web page and configure the Data Indexer, do the following:
1. Log in to the DPX appliance as an administrator.
2. Start one of the supported Internet browsers.
3. Type the following in the address bar: localhost:9100
The Data Indexer Configuration sign in page is displayed.
4. Type admin in the Username box and the LogRhythm default password in the Password box, and then
click Sign In.
Relay Config
These values can be left at their defaults.
Carpenter Config
Parameter Value
Db Password This is the password used by the LogRhythmNGLM SQL account. Services on the Data Indexer use this account
to connect to the EMDB and read/update tables.
NOTE: It is highly recommended and LogRhythm best practice to change all MS SQL account passwords
when setting up a deployment. After you change the LogRhythmNGLM password in Microsoft SQL
Server Management Studio, you must set Db Password to the same value. You should change the
password in Microsoft SQL Server Management Studio first, then change it on the Data Indexer
page.
Db Username This should be left unchanged unless you have renamed the LogRhythmNGLM SQL account in SQL Server
Management Studio.
Emdb Host This must be set to the external IP address of your Platform Manager appliance, where the EMDB database is
hosted.
Minutes To Rest This can be left at the default value.
Sql Paging Size This can be left at the default value.
6. Click Submit.
Your changes will be pushed to the appropriate appliances and database tables, and all of the required
Data Indexer services will start or restart.
4. Type admin in the username box and the LogRhythm default password in the password box, and then
click Sign In.
Relay Config
These values can be left at their defaults.
Carpenter Config
Parameter Value
Db Password This is the password used by the LogRhythmNGLM SQL account. Services on the Data Indexer use this account
to connect to the EMDB and read/update tables.
NOTE: It is highly recommended and LogRhythm best practice to change all MS SQL account passwords
when setting up a deployment. After you change the LogRhythmNGLM password in Microsoft SQL
Server Management Studio, you must set Db Password to the same value. You should change the
password in Microsoft SQL Server Management Studio first, then change it on the Data Indexer
page.
Db Username This should be left unchanged unless you have renamed the LogRhythmNGLM SQL account in SQL Server
Management Studio.
Emdb Host This is the external IP address of your Platform Manager appliance, where the EMDB database is hosted. If you
leave the default value of 127.0.0.1, the Data Indexer services will attempt to connect locally to the EMDB, but it
does not exist locally.
Minutes To Rest This can be left at the default value.
Sql Paging Size This can be left at the default value.
6. Click Submit.
Your changes will be pushed to the appropriate appliances and database tables, and all of the required
Data Indexer services will start or restart.
NOTE: You should assign all Data Processors to a cluster, offline, active, and archive. If you need to restore any
data using SecondLook, the archive Data Processors must be assigned to a cluster.
4. Select a cluster from the Cluster Name list, and then click OK.
NOTE: Cluster information is sent out when applying configuration changes on the Data Indexer. Refer to
Configure the Data Indexer for more information.
2. Ensure log data is being received by viewing the log data in the Tail display.
3. Configure the Tail to query all available log sources for the last 24 hours. Do not configure any filters.
4. Ensure logs are being processed by double-clicking a row in the Log/Event List pane, and checking for
metadata parsing and classification. It is sufficient to just verify that there is some data loaded into the
fields on the Processed Metadata Fields tab.
5. Verify Event Forwarding by opening the Personal Dashboard and viewing events as they arrive.
6. Visually check system health and status by opening the Deployment Monitor. The Deployment Monitor
provides statistics about log collection and system resource usage.
NOTE: Log collection happens from the older date to the newer date. If no data is present, repeat the Tail
using a timeframe further in the past. It may take your LogRhythm appliance several hours to catch up to
the present after collection begins.
Additional Tasks
1. Activate and register the Microsoft Windows operating system on the appliance.
2. Ensure that you have the latest LogRhythm software, especially if there was a time lapse between the
receipt and the setup of the appliance.
4. Run Microsoft Windows Update to confirm that you have the latest Microsoft updates installed on the
appliance.
Disclaimer
The information contained in this document is subject to change without notice. LogRhythm, Inc. makes no warranty of any kind with respect to this information.
LogRhythm, Inc. specifically disclaims the implied warranty of merchantability and fitness for a particular purpose. LogRhythm, Inc. shall not be liable for any direct,
indirect, incidental, consequential, or other damages alleged in connection with the furnishing or use of this information.
Trademark
LogRhythm is a registered trademark of LogRhythm, Inc. All other company or product names mentioned may be trademarks, registered trademarks, or service
marks of their respective holders.