2014-01-10 03:27 AM
As we have 60 Domain Controllers in the environment, can all these DC's join the RSA Security Analytics Server automatically
or in other words all the server's in the domains can join SA automatically.
So if we want all the DC or servers to connect to SA do we need any agent to install on the Windows Server to push the logs to SA, or did we need to do anything on the SA side?
2014-01-10 02:35 PM
They have actually made this easier in SA compared to envision.
First off, it is all agentless and SA is going to pull the data.
Second, it is done by domain, then by host.
You will also need to configure a log collector to gather all of this information, not just a log decoder. Don't worry this does not cost extra money.
You can also import all of this by using a csv file with the correct information attached to it. So for the domains it would need to look like
Headers
alias,authMethod,username,password,channel,pollingInterval,readAllEvents,renderEvents,maxEventsPerCycle,maxDuratio nPerCycle,COLUMN HEADERS
"Test","basic","testuser@TEST","testpassword","","180","true","true","5000","120"
You can use the same csv method for adding each host to that domain.
One thing I am not sure of is why it wants you to specify if a system is a windows domain controller or not, we have not begun the full integration of our windows hosts into SA so our DC's are still linked to enVision.
A few links to help out
2014-01-10 10:23 AM
same domain? then just added the windows collector
2014-01-10 02:35 PM
They have actually made this easier in SA compared to envision.
First off, it is all agentless and SA is going to pull the data.
Second, it is done by domain, then by host.
You will also need to configure a log collector to gather all of this information, not just a log decoder. Don't worry this does not cost extra money.
You can also import all of this by using a csv file with the correct information attached to it. So for the domains it would need to look like
Headers
alias,authMethod,username,password,channel,pollingInterval,readAllEvents,renderEvents,maxEventsPerCycle,maxDuratio nPerCycle,COLUMN HEADERS
"Test","basic","testuser@TEST","testpassword","","180","true","true","5000","120"
You can use the same csv method for adding each host to that domain.
One thing I am not sure of is why it wants you to specify if a system is a windows domain controller or not, we have not begun the full integration of our windows hosts into SA so our DC's are still linked to enVision.
A few links to help out
2014-09-05 11:42 AM
The links in the above post are stale. Please see the same topics here: