Professional Documents
Culture Documents
2 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Before Building Content
• Logger evaluations do tend to revolve around
• ‘High’ inbound event collection
• Easily proven, just apply their event sources
• Seeing ‘their’ data
• If ‘their’ data is standard event sources then use SmartConnectors
• If ‘their’ data is non standard event sources FlexConnectors will be needed
• Attend the HP ESP FlexConnector Training Course
• See ‘Outlining PoC’s’
• Log retention in the long term
• Covered as a capability pre-PoC and technically post-PoC at the sizing stage
• Do use the PoC to gather ‘real’ event rate data, this will assist in accurate sizing
3 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger Labs
• Practical exercises will focus on:
#1 Fast searches and visualization
• “Where is my data and what does it look like?”…………………Statistic's and metrics
#2 Dashboards
• “Can I see graphical data ?”…………………………………………….Monitoring activity
#3 Reports
• Customize and run reports…………………………………………......Reporting capabilities
#3 Augment Logger search results with data available in external file
• How to combine intelligence with Logger searches…………….Static correlation
• This applies to standard or custom data
• If you expect to use custom data then attend the FlexConnector Training!
4 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Search
Get familiar with Search
Free text
(no field defined)
Structured
(field defined)
5 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
What can I do in a Search?
6 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Field Set: grouping CEF columns into a set
7 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Use Field Summary to show quick data overview
Drilldown in to a field
8 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Use Field Summary to show quick data overview
Drilldown in to a field
9 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Search
Learn to build
your own queries
10 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Search
Use the
Advanced
Search
Especially for
structured search
Use the
Demo script
–It is a good guide
11 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Search
Use the
Advanced
Search
Especially for
structured search
Use the
Demo script
–It is a good guide
12 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Pipeline Search Operators
Lots of options
The dropdown
help is good!
13 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Pipeline Search Operators
Use Chart to
‘visualise’
searches
14 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
15 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Top User Accounts Modification by Source User Name
16 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger lab #1
Searches
Lab #1: Search and drill-down results
Use Case: Find all configuration modifications applied in the last hour to different devices in a same network.
Then investigate by drilling down configurations modified successfully across results.
What is expected ? A uniform and consistent set of results using HP ArcSight categorization from different log
sources generating different log formats
What content do we need here? collected and parsed events – search feature – drill-down feature
1. From Analyze Search menu window type categoryBehavior = /Modify/Configuration and click on GO
Results show all configuration modification events in the last 10 minutes – we rerun the search on the last hour
2. Select categories from drop down list System Field Sets in upper screen, then click Update Now
3. Click on categoryOutcome (we see now % in Successes, Failures and Attempts)
4. We are interested in successful modifications, therefore Click on Success in selected Fields list
Notice our search being automatically updated
All successful changes applied to different devices in the last hour will show-up
5. Search for any entry where categoryDeviceGroup field/column is populated with Firewall
6. Click on Firewall field/column and notice our search being automatically updated
7. Now on left side of your screen select Name field from Selected Fields list
A list will containing different vendors syntax when same type of event happens
8. Click on « Policy modified » and see the results
Notice
18 the
© Copyright 2015hit number
Hewlett-Packard decreasing
Development asinformation
Company, L.P. The we narrow ouris subject
contained herein search to change without notice. HP Restricted. For HP and Partner Internal Use
Dashboards
Event Data Visualization
20 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Dashboard Panels
First run searches with PIPE operator
21 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Dashboard
Click to “Save the Current Filter”
(*) When search uses the pipeline operator then Dashboard panel button shows-up
22 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Dashboard
• 2- Select “Dashboard Panel Button”
• Provide a “Panel Title”
• 3-Select “New Saved Search”
• Provide a ‘Saved search name’
• 4-Select ‘New Dashboard’
• Provide a Dashboard name
• 5-Select ‘Panel type’ (chart or table or even both)
• 6-Select ‘Chart type’ (column, Bar, Pie, Area, …)
• 7-Select Chart limit
• 8-Click “Save”
A new One Panel Dashboard was created
23 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Displaying a previously created Dashboard
24 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Dashboard
25 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Modifying Dashboard
26 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Modifying Dashboard
Click on “Tools”
Select to “Change Layout”
• Click “Save”
27 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Dashboard
Looks okay
But there seems to be some ‘null’
field data skewing the graph
28 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Modifying Dashboard
Click on “Configuration”
–Select “Settings”
29 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Modifying Searches
Select your saved search
30 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Editing Query
Edit the Query
31 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Run Modified Query
Load and run the Query
32 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Modified Search
Modified Search Results
33 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Advanced Search UI TIP
I used “Advanced Search” under the
! Analyze Tab to determine the search
syntax.
34 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger lab 2 #: Create Dashboard
Use Case: Create and display a dashboard reflecting login activity during the last day
What is expected? A Dashboard will show up with 5 panels (4 Searches are being created and saved)
What content do we need here? 4 created and saved searches. 1 Dashboard with 5 panels.
Panel#1 : Pie chart with login activity (logins success/failure/attempt)
Panel#2 : Column chart with login successes by User
Panel#3 : Column chart with login failures by User
Panel#4 : Bar Chart with logins by Device Product……….(same search will display panel#4 and panel#5)
Panel#5 : Table with logins by products…………………….. (same search will display panel#4 and panel#5)
Reports
Reports
38 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Export results
39 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Simple Reports
40 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Reports
Logger Out-Of-the-Box has :
dozens of reports
a slew of filters, some field sets
a few system dashboards
41 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Reports
• Repeatable, Structured Reporting
• Logger Reporting works on Structured data only NAVIGATION
Allow users to browse and selected
reports they are interested in
• A Report is built upon a Report Query
– A Query can contain a Parameter (at run-time, specify a value)
43 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Reports during PoC
•Find a report that provides similar
information/context
44 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Reports during PoC
•Save the report under
a different name
45 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Reports
•Select Expand All
•Edit the “Display Fields”
• Remember to “Save”
46 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating Reports
•Select “Preview”
47 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Creating/Modifying Queries
• In this example we will
modify an existing report
named ‘User Investigation’
48 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Modifying Queries
Select report
Click on Customize
Select Data Source
Edit Query
Result will
check the Query
Let’s get back to
Properties
49 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Modifying Queries
•Select “Design”
• Click “OK”
51 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Reports
Logger reports can be highly customised
–Format - Chart/Table
–Query (with SQL Editor)
–Prompt
–Group/Sort/Filter
–Drilldown (to further report)
52 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger lab 3 #: Customize and Run Report
Use Case: Modify existing report “Failed Logins by User” and run with saved changes
What is expected? A previously existing report parameters are modified then report is run
What content do we need here? Failed Logins by user report.
1. Select Report from main menu or type Rep in the Take me to windows then click Reports
2. In left Navigation section click Report Explorer
3. Select Default Reports group under Root folder and click on Failed Logins by User report template
4. In Actions section click Customize Report and click Save as – give a meaningful name - and click Save
Report has been copied
5. Click Open (a new window will open) and select your copied report from list (name just provided)
Copied report will open (notice report name shows up on top of windows)
6. Click Expand All
From here you can see/modify the Query, Fields and Filter Criteria's, … and all that applies to this report
7. In Select Display Fields add categoryDeviceGroup to the Selected Fields group
8. In Select Filter Criteria change Count Above 5 to 2, Add filter destinationUserName Is Not NULL, add filter
destinationHostName Is Not Null, add filter destinationAddress Is Not NULL
9. Click Save (copied report has been modified)
10. Click on RUN
53 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger lab #4
Row n
louis 62.25.67.111 007 non
Any subsequent row that does not contain the same number of comma-separated values as
the first row will be skipped during the search by the lookup operator*
*If a search using the lookup operator needs to skip one or more rows, a warning message displays on the search page
56 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Look up file – Deep Dive
• Lookup filenames can contain only alphanumeric characters and underscore, and must not begin with a number. Do not include +, -,
or * in the filename. These characters are reserved for the lookup command.
• The maximum size Lookup file that can be uploaded is 50 MB (uncompressed or compressed)
• The maximum disk space allocated for storing Lookup files is 1 GB (cap on overall disk space allowed for storing all Lookup files)
• Maximum number of Lookup entries is 5,000,000. For example, if a Lookup file has four columns and ten rows, the total number of
lookup entries is 4x10=40.
57 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Searches with Look up file - Deep Dive
• When a Lookup file is used in the search, all of its entries will be loaded into memory.
• It is worth noting that the maximum number of rows loaded for lookup varies depending on the
number of columns in the Lookup file.
• the maximum number of rows allowed for lookup will be 5,000,000/500 = 10,000 rows
• any subsequent rows will not be used !
• Then the maximum number rows allowed for lookup will be 5,000,000/4 = 1,250,000 rows
58 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Searches with Look up file Illustrated
search
59 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Searches with Look up file Illustrated
3-Results (if any) are
loaded in memory
60 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Searches with Look up file Illustrated
4-Logger scans entries in
uploaded look up file
61 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Simple Search with Look up file
62 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Searches with Look up operator
... | lookup [+/-/*] lookupTableName externalField1 [as loggerField1] [, externalField2 [as
loggerField2] ...] [output [ * | externalField1, externalField2... ] ]
OPERATOR DESCRIPTION
Selects events where the value in the Lookup field
+ (loggerField1, loggerField2) is identical with that in the
uploaded Lookup file (externalField1, externalField2).
63 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP
If you doand
notPartner Internal
specify +, -,Useor *, + is used.
Simple Search with Look up file
64 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Tor Exit Nodes
Download and Import CSV files
https://www.dan.me.uk/tornodes (no more than 30 minutes old)
https://torstatus.blutmagie.de/
65 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Tor Exit Nodes Look Up file
66 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger lab 4-a #: Run Search with Lookup File (static correlation)
Use Case: Detect BAD IP addresses inbound connections on port 443 on internal hosts during last 2 hours
What is expected? A search results matching look up file entry(ies) containing BAD IP addresses with details
What content do we need here? A populated Look up file – received events – a search with | lookup operator
1. Select Search from Analyze main menu or type S in the Take me to windows then click Search
2. In Search windows type destinationPort=443 then click GO
Likely tons of results. We need narrowing our search using a look up file named “Malicious_Addresses”
But first see what is inside a lookup file
3. Type Lo in the Take me to windows then click Lookup Files
4. Click Malicious_Addresses and see how lookup file schema was created (columns, data type in each column, …)
Now get back to your search (Search from Main Menu Analyze or type S in the Take me to windows) then click Search
5. Type destinationPort=443 | lookup Malicious_Addresses ip as sourceAddress output * then Click GO
……We ran that same search but we added the lookup feature ( | lookup ) with Malicious_Addresses file.
Search results display now only events where sourceAddresse of events match ip addresses from the lookup file
67 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Logger lab 4-b #: Creating Lookup File
Use Case: Create a new lookup file from suspicious inbound connections on internal hosts
What is expected? A search results exported (CSV format)
What content do we need here? A populated Look up file – received events – a search with | lookup operator
68 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
69 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
70 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
71 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
72 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
73 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
74 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
75 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
76 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
77 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
78 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
79 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
80 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
81 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
82 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
83 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
84 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
85 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
86 © Copyright 2015 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use
Thank You
Questions ?
© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Restricted. For HP and Partner Internal Use