2020-01-12 02:11 AM
Hi all,
I'm new with NW and I have a couple of basic questions.
I'm trying to deploy NW on AWS so, for now, I succeed to install and login to the NW platform using the Lite Version.
Q: How can I get the full version? what are the differences?
Q: Does the ISO need to be the same version as the server?
Q: I want to forward Syslog from Fortigate, which component I need to configure?
Q: Is it a Log collector/Log Decoder/Hybrid Log Collector? What are the differences between these services?
Q: I deploy Remote Log Collector from the public AMI, is it necessary? or that I can forward logs to port 514 in the NW server?
I'm trying to install services using the UI, Admin>Host>Install> Log Collector but it keeps failing, it's not something the wrong with log collector because when I tried to install any other service its also failed.
Q: What can be the problem?
Thanks!
2020-01-13 09:49 AM
I am not familiar with what you mean by "Lite" version. As far as I know, we only have one version.
At the time of this writing, the way you get the Admin Server in Azure and AWS should be done through Sales as we make every image except this device available in the cloud. To setup anything, you need an Admin Server first. This device provides UI access and other functionality but does not collect log/packet data itself. Are you trying to setup an Admin Server or just the log collector in Azure?
You will want all components to be on the same version when installing. 11.3.0.2 would be a good start.
A log collector collects the logs and forwards them to a Log Decoder for parsing. Once parsed from a Log Decoder, they are moved to a Concentrator for Investigating and Reporting. The Log Hybrid is the conglomeration of these items but I recommend in a Virtual Machine environment that you setup these as different hosts but note that a Log Decoder will always have a Log Collector. You can setup additional log collectors in other subnets, for instance, if the Log Decoder is not reachable from it. This is only one of a few use cases where you would need a stand alone Log Collector.
Please note that if you go down this road and you encounter issues along the way, you can always open a RSA Support case and discuss with me or another individual if you have more questions.